Trellix DLP Discover can run on physical or virtual servers. You can install one or more Discover servers on your network using ePO - On-prem ePO - SaaS (recommended) or manually.
Large networks typically divide the workload by LAN or workgroup, and Trellix DLP can assign different policies to different groups. Reporting can be by group, or a rollup data server task can collect data from several servers to produce a single report.
Make sure that any servers you use for Trellix DLP Discover meet these requirements:
The server has Trellix® Agent installed and running.
The server is communicating with ePO - On-prem.
The server is added to the ePO - On-prem System Tree.
Do not run other Trellix DLP server software on the same physical or virtual server.
Trellix DLP Discover software can be installed in one of two roles: Trellix DLP Discover server or DLP Server. The difference between a Trellix DLP Discover server (one that can run scans) and a DLP Server (a registered database server) is the server role. Setting the server role is done automatically when you install or upgrade from ePO - On-prem. When installing DLP Server manually, use this command:
DiscoverServerInstallx64.exe ROLE=DLP
Trellix DLP Discover has an optional Optical Character Recognition (OCR) add-on package for extracting text from image files and scanned images saved as PDF. The add-on is installed separately in the ePO - On-prem repository and deployed to the server after deploying the Trellix DLP Discover server software. When updating, you must also update the OCR package, as it is automatically deleted when you update the server software.
DLP Servers use HTTPS as a secure communications channel with other Trellix servers, and therefore must have Microsoft Internet Information Services (IIS) installed. To use the registered documents feature, the DLP Server used to match Registered Documents content fingerprints must also be specified on the Registered Documents page of the server configuration in the Policy Catalog.
Trellix DLP Discover performs cryptographic operations in a way that is compliant with FIPS 140-2. Cryptographic libraries bundled with Trellix DLP Discover always have FIPS mode enabled without any option to disable it. To enable FIPS mode on Windows, refer to the published Security Policy Document for the applicable platform which can be found at the NIST Validated Modules web site. For additional information, refer to the Microsoft FIPS 140-2 Validation documentation.
For information about installing and running Trellix Agent, see the Trellix Agent Installation Guide and Trellix Agent Product Guide.