Using the configure a scan wizard

Prev Next

This topic demonstrates how to configure a scan using the Configure a Scan wizard. It uses the example of a scheduled scan that will run on the Laptops folder in the Assets share. Files with the .doc, .docx, .pdf, .ppt, and .xls file type that were added or modified since August 1, 2014 will be scanned every Sunday at 4:00 a.m. Files with the .apk type will be moved to a whitelist. Malicious, non-malicious, and whitelist files will be moved to the specified folders.

Note

To navigate through the wizard steps, use the Next and Previous buttons or click the target step button.

Open the wizard

  1. Click the Scans tab.

  2. Click Configure a Scan.

FX_Wizard_OpenIt_scap.png

Name of scan

This step names the scan and defines its initial scope.

FX_WizardName_scap.png
  1. (Optional) Type a name to identify the scan. The name does not have to be unique.

  2. Select the storage you want to scan. Each option includes the storage name, server name or IP address, and share name.

  3. To scan only a specific folder and its subfolders, type the folder name.

  4. Click Next or Filter this Scan to advance to the next step.

Filter this scan

This step allows you to control the scope of the scan, as described in Scan filters.

FilterAScanFX.png
DynamicAnalysisFX.png
  1. Select the file types you want to scan. This list shows file types that are enabled on Settings: Malware File Assoc. page for at least one guest images profile. If no file types are selected, files of all types are scanned.

    Caution

    If you select a file type that is later disabled on the Settings>Malware File Assoc. page, subsequent scans will skip those files.

  2. Select the file types you consider safe and want to whitelist. This list shows all the file types that the File ProtectFile Protect appliance knows about.

  3. Click theDynamicAnalysisIconFX.png icon to expand the Configure Dynamic Analysis option. This list shows the default file types you can select for dynamic analysis at the appliance level.

  4. Click the FX_Calendar_icon.png icon and select a date to specify how far back in time you want the appliance to look for new or modified files to scan.

  5. Click Next or Scan Results Location to advance to the next step.

Note

You can also configure file types for dynamic analysis at the appliance level in Settings > Guest Images section.

SettingsGuestImagesDAFX.png

Scan results location

This step defines the folders the File Protect appliance should move files to after they are scanned, described in Scan results folders. The appliance does not scan these folders.

FX_WizardResults_scap.png
  1. Select one or more of the following folders:

    • A Quarantine File Location folder to store malicious files after they are analyzed.

      Important

      You can select either a quarantine share you added as storage or "local_QF." If you select "local_QF," the File Protect appliance will create a local_QF folder in the source file share the first time it encounters a malicious file, and will move all malicious files into it. Trellix recommends against using "local_QF," because malicious files will not be isolated from the source files.

    • A Good File Location folder to store non-malicious files after they are analyzed.

    • A Whitelist File Location to store files with file types you selected in the File Types to Whitelist section in the Filter this scan step.

    • An Unknown File Location to store files with file types you did not select in the Select Specific File Types to Scan section in the Filter this scan step, file types the appliance does not recognize, files that are empty, and so on.

  2. Click Next or Scan Type to advance to the next step.

Scan type

This step defines the type of scan, as described in Scan types.

FX_WizardType_scap.png
  1. Click one of the following buttons:

    • Pre Scan performs a preliminary scan of the share.

    • Scan Now performs an instant scan.

    • Continuous performs a scan at regular intervals.

    • Schedule a Scan performs a daily or weekly scan as configured.

  2. If you selected Schedule a Scan, do one of the following:

    • Select Daily, and then select the hour (0-23) and minute (0-59) the scan should start.

    • Select Weekly, and then select the day, hour, and minute the scan should start.

  3. Click Next or Scan Configuration Confirmation to advance to the next step.

Scan configuration confirmation

This step shows you a summary of the scan parameters you defined and allows you to save or start the scan.

FX_WizardConfirm_scap.png
  1. Review the summary information.

  2. If you need to make changes to a step, click Previous or the step button to return to it.

  3. Pre-Scan, Scan Now, or Continuous Scan: Click Save Scan if you want to run the scan later, or Scan Now to run the scan immediately.

  4. Schedule a Scan: Click Schedule Scan.

  5. After the "Scan configuration complete" message is displayed, click the FX_WizardClose_icon.png icon at top right corner to close the wizard.

Note

To cancel the configuration of a scan, simply close the wizard by clicking the FX_WizardClose_icon.png icon.