Using rules with scans

Prev Next

Remediation scans use rules to detect and act on sensitive files.

Files crawled by a remediation scan are compared against active discovery rules. If the file matches the repository and classifications defined in a rule, Trellix DLP Discover applies the Action specified in the rule.

Actions available for remediation scans

Action

File System

SharePoint

Box

Database

Take no action

X

X

X

X

Create an incident

X

X

X

X

Store the original file as evidence

X

X

X

X

Copy the file

X ¹

X ¹

X ¹

Move the file

X ¹

X¹ ²

X ¹

Apply an RM policy to the file

X

X ²

X

Classify File As

X

X

X

Remove automatic classification

X

X

X

Remove anonymous sharing for the file

X



¹ Copying and moving files supported only to SMB/CIFS shares.

² Not supported for SharePoint lists; supported only for files attached to SharePoint lists or stored in document libraries, and to SMB/CIFS only. Some file types used for building SharePoint pages, such as .aspx or .js, cannot be moved or deleted.