The Trellix DLP Endpoint client software for Trellix Agent resides on enterprise computers and executes the defined policy. The software also monitors user activities involving sensitive content. Client configuration is stored in the policy, which is deployed to managed computers.
Note
The Policy Catalog comes with Trellix default policies for Windows and macOS endpoint configurations and DLP policy. Click Duplicate (in the Actions column) to create an editable copy as a base for your policy.
The client configuration is stored in the policy, which is deployed to managed computers by ePO - On-prem. If the configuration is updated, you must redeploy the policy.
Client Service WatchDog
Note
The Client Service WatchDog is not supported on Trellix DLP Endpoint for Mac.
To maintain normal operation of Trellix DLP Endpoint software even if there is malicious interference, Trellix DLP Endpoint runs a protective service called the Client Service WatchDog. This service monitors the Trellix DLP Endpoint software, and restarts it if it stops running for any reason. The service is enabled by default. If you want to verify that it is running, look in the Microsoft Windows Task Manager processes for the service named fcagswd.exe.
Ignore lists in client configuration
Ignore lists in the client configuration exclude the listed processes, extensions, or URLs from rules.
Setting | Ignore List | Description |
|---|---|---|
Clipboard Protection Applies to both Windows and macOS clients | Ignored Processes | Trellix DLP Endpoint ignores clipboard operations performed by the listed applications. |
Content Tracking Applies to both Windows and macOS clients | Ignored Processes | Trellix DLP Endpoint ignores access to files performed by the listed applications. |
Printing Protection Applies to both Windows and macOS clients | Ignored Processes | Trellix DLP Endpoint ignores printing actions performed by the listed applications. |
Web Protection Applies to both Windows and macOS clients | URL Ignore list and Web URL tags list | Lists URLs excluded by the browser plug-in from all web protection rules. You can add multiple ignore lists by domain, IP address range or by URL tags |
Client configuration settings
Client configuration settings determine how the endpoint software operates. Most of the client configuration settings have reasonable defaults that can be used for initial setup and testing without alteration.
Tip
To verify that the client configuration settings continue to meet your requirements, review them at regular intervals.
The following table lists some of the more important settings to verify.
Setting | Details | Description |
|---|---|---|
Advanced Configuration | Run DLP client in Safe Mode Applies to Windows clients only | Disabled by default. When enabled, Trellix DLP Endpoint is fully functional when the computer is started in Safe Mode. A recovery mechanism exists in case the Trellix DLP Endpoint client causes a boot failure. |
DLP access protection | When enabled, activates the DLP data access protection features. Default: Enabled in both Trellix Device Control and full Trellix DLP Endpoint. | |
Show challenge response on upgrade Applies to both Windows and macOS clients | When enabled, activates the challenge/response pop-up window on upgrade. | |
Show challenge response on uninstall | When enabled, activates the challenge/response pop-up window on uninstall. | |
Run DLP client watch dog Applies to both Windows and macOS clients | When enabled, monitors the endpoint processes and restarts them if closed. Changing this setting requires a client computer restart. | |
Run DLP client service watch dog Applies to both Windows and macOS clients | When enabled, monitors the watch dog and restarts it if it closes. Changing this setting requires a client computer restart. | |
Agent Bypass Applies to both Windows and macOS clients | Stops the agent bypass when a new client configuration is loaded. Deselected by default. | |
Advanced Pattern Settings | When enabled, activates regex case sensitivity. To apply case sensitivity with any regular expression, the regex pattern must begin with (?i). You can also edit the existing regex pattern and append (?i) at the beginning of the pattern.
| |
Content Tracking Applies to both Windows and macOS clients | Use the following fallback ANSI code page | If no language is set, the fallback is the default language of the endpoint computer. |
Corporate connectivity Applies to both Windows and macOS clients | Corporate Network Detection Corporate VPN Detection | You can apply different prevent actions to endpoint computers in the corporate network or outside the network. For some rules, you can apply different prevent actions when connected by VPN. To use the VPN option, or to determine network connectivity by corporate server rather than by connection to ePO - On-prem, set the server IP address in the relevant section. |
Device Control | iPhone Protection Mode | Allows or prevents charging iPhones when the device rule action is Block. |
Device Control Settings | Allows the administrator to choose whether to apply Device Control policies immediately when the policy is applied, or to apply them only when the computer is restarted or the device is physically or logically enabled or disabled. | |
Debugging and Logging | Log DLP events to external HTTP server Applies to both Windows and macOS clients | Use these settings to configure the server receiving raw data from the Trellix DLP Endpoint client. |
Syslog Server Settings | Configure a Syslog server path used for logging certain types of Trellix DLP Endpoint events. The events are sent whether rules are configured to trigger the events or not. The following actions are sent automatically when Send DLP Syslog events to Syslog server is enabled:
| |
Email Protection Applies to Windows clients only | Email Caching | Stores tag signatures from emails to disk to eliminate re-parsing emails. |
Email recipients | Sets the maximum number of email recipients to report. Default is 10. | |
Email Handling API | Outgoing email is handled by either Outlook Object Model (OOM) or Messaging Application Programming Interface (MAPI). OOM is the default API, but some configurations require MAPI. | |
Outlook 3rd party add-in integration | Sets integration with either Titus or Bolden James email classification software. | |
Outlook Background Processing (Only for DLP 11.6 and later) | Enable background processing of emails to reduce user impact when sending emails using Microsoft Outlook. Set the maximum amount of time allowed to analyze the emails.
Enable a pop-up message that allows the end-user to either review a blocked email or to discard it. Enabling this pop-up message overrides the notification configurations defined in the Email Protection rule. Set the action taken to either send the email or to block it if the analyzing time exceeds. | |
Email Timeout Strategy | Sets the maximum time to analyze an email and the action if the time is exceeded. | |
Outgoing Email User Notification | Sets the end user notification message and when it is displayed. | |
Shared Storage and Evidence Applies to both Windows and macOS clients | Shared Storage | Select SMB (UNC) or WebDAV (URL) and provide the shared storage location.
Specify this path to store:
|
Client Settings | You can change the way hit highlighting is displayed by setting classification matches to all matches or abbreviated results. | |
Incident Information | You can hide or display the short match string in the incident details. The setting works in real time, that is, if you change the setting, it only affects the display for incidents collected from that point forward. | |
Operational Mode and Modules Applies to both Windows and macOS clients | Operational Mode | Set Trellix Device Control or full Trellix DLP Endpoint mode. Reset this parameter if you upgrade or downgrade licensing. |
Data Protection Modules | Activate required modules.
| |
Operational Mode and Modules Applies to Windows clients only | Browsers | Enables the browsers you want to block or monitor data upload when using Web Protection rules. Supported browsers are Microsoft Internet Explorer, Google Chrome, Microsoft Edge (Chromium-based), Mozilla Firefox, and Island (Beta). Default: All browsers are selected except Island browser.
|
Browser Address Bar URL detection | This feature is used to control a major cause of high CPU utilization. The default is to enable browser address bar URL detection. If high CPU utilization is encountered, you can disable the feature. | |
Plug and Play Applies to Windows clients only | iPhone Protection Mode | Selects whether or not a blocked iPhone can be charged. This setting applies to plug and play device rules. |
Web Protection Applies to Windows clients only | Web protection evaluation | Select inputs for web request evaluation when matching web protection rules. These settings allow blocking requests sent by AJAX to a different URL from the one displayed in the address bar. At least one option must be selected. |
Process HTTP GET requests | GET requests are disabled by default because they are resource-intensive. Use this option with caution. | |
Web Timeout strategy | Sets the web post analysis timeout, action to perform if timeout is exceeded, and optional user message. | |
URL Ignore List | Create ignored URL lists and select which list to exclude from web post protection rules. | |
Disable Drag and Drop Applies to Windows clients only | When enabled, prevents the drag and drop of attachments from Outlook to supported Chromium browsers. | |
Web URL tags list Applies to Windows clients only | Include or exclude URL tags to monitor specific URLs for sensitive content. For additional information on finding tags for other websites, see KB96881 |
Troubleshooting guidance for Trellix DLP Endpoint
Use the Troubleshooting page in Windows client configuration for tips and guidance on actions that you can take to troubleshoot performance issues and tune policies in Trellix DLP Endpoint.