<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EFR: forensic recorder is working on excluded Paths in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/EFR-forensic-recorder-is-working-on-excluded-Paths/m-p/218322#M8825</link>
    <description>&lt;P&gt;OKay, thanks a lot. I just will go on and update the client. Lets see what happens&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you very much so far&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jun 2024 06:56:56 GMT</pubDate>
    <dc:creator>SWBW_Florian</dc:creator>
    <dc:date>2024-06-21T06:56:56Z</dc:date>
    <item>
      <title>EFR: forensic recorder is working on excluded Paths</title>
      <link>https://community.checkpoint.com/t5/Endpoint/EFR-forensic-recorder-is-working-on-excluded-Paths/m-p/217003#M8807</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;today we observed issues with the Exclusions of the forensic recorder.&lt;/P&gt;&lt;P&gt;Were using a Backupsystem built by commvault. Harmony is very intense in working on those processes so they will fail and files got deleted during backups and general activity of the commvault software.&lt;/P&gt;&lt;P&gt;So i created Exclusions for our Backup-Server.&lt;/P&gt;&lt;P&gt;I excluded, at the end, the whole Software folder C:\Program Files\Commvault\ at:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Forensics: Quarantine Exlusions&lt;/P&gt;&lt;P&gt;Forensics: Anti Ransomware&lt;/P&gt;&lt;P&gt;I also added at Forensics: Monitoring&lt;/P&gt;&lt;P&gt;C:\Program Files\Commvault\*.exe&lt;/P&gt;&lt;P&gt;But i can still see with the ressource monitor of windows that the service EFR is working in those folders&lt;/P&gt;&lt;P&gt;Is the rule not accepted/working? Or ignored? Or buggy?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because of the EFR Processes some of the jobs are falling into timeouts. This is a problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you give me a hint on how to configure the EFR in a right manner?&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;kind regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Florian&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 12:38:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/EFR-forensic-recorder-is-working-on-excluded-Paths/m-p/217003#M8807</guid>
      <dc:creator>SWBW_Florian</dc:creator>
      <dc:date>2024-06-10T12:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: EFR: forensic recorder is working on excluded Paths</title>
      <link>https://community.checkpoint.com/t5/Endpoint/EFR-forensic-recorder-is-working-on-excluded-Paths/m-p/217008#M8808</link>
      <description>&lt;P&gt;This might be worth TAC case.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 13:26:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/EFR-forensic-recorder-is-working-on-excluded-Paths/m-p/217008#M8808</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-10T13:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: EFR: forensic recorder is working on excluded Paths</title>
      <link>https://community.checkpoint.com/t5/Endpoint/EFR-forensic-recorder-is-working-on-excluded-Paths/m-p/217037#M8809</link>
      <description>&lt;P&gt;Where precisely did you try to define the exclusion?&lt;BR /&gt;I'd read this SK, which might shed some light on why this isn't working the way you expect:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk128472" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk128472&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 18:05:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/EFR-forensic-recorder-is-working-on-excluded-Paths/m-p/217037#M8809</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-10T18:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: EFR: forensic recorder is working on excluded Paths</title>
      <link>https://community.checkpoint.com/t5/Endpoint/EFR-forensic-recorder-is-working-on-excluded-Paths/m-p/217038#M8810</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Which client version are you using?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 18:11:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/EFR-forensic-recorder-is-working-on-excluded-Paths/m-p/217038#M8810</guid>
      <dc:creator>AdiGH</dc:creator>
      <dc:date>2024-06-10T18:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: EFR: forensic recorder is working on excluded Paths</title>
      <link>https://community.checkpoint.com/t5/Endpoint/EFR-forensic-recorder-is-working-on-excluded-Paths/m-p/217048#M8812</link>
      <description>&lt;P&gt;First the disclaimer ......... In general it best to have a full investigation of the issue; rather than just referring to a specific fix that would require an upgrade and may not address the issue. Also, not clear what version of client is being used.&lt;/P&gt;
&lt;P&gt;However, since there was a recent fix released that seems very similar to this issue I will call it out and maybe relevant information for other people as well. It can be applicable to clients running E88.00 and later releases and there is a fix included in E88.31&lt;/P&gt;
&lt;P&gt;See &lt;A href="https://support.checkpoint.com/results/sk/sk182277" target="_blank"&gt;sk182277&lt;/A&gt; for more information on this release. Specifically includes the following fix that may be related to this issue:&lt;/P&gt;
&lt;TABLE id="resolved2Table" class="footnote" border="1" width="100%" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;AHTP-30676&lt;/TD&gt;
&lt;TD&gt;Some processes specified through the Monitoring and Exclusions action in the Policy are not fully excluded by the Forensics component from analysis as intended.&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Mon, 10 Jun 2024 19:38:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/EFR-forensic-recorder-is-working-on-excluded-Paths/m-p/217048#M8812</guid>
      <dc:creator>JonnyRabinowitz</dc:creator>
      <dc:date>2024-06-10T19:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: EFR: forensic recorder is working on excluded Paths</title>
      <link>https://community.checkpoint.com/t5/Endpoint/EFR-forensic-recorder-is-working-on-excluded-Paths/m-p/217116#M8814</link>
      <description>&lt;P&gt;were using client version 87.60 so maybe that fix wont suit here?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 12:43:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/EFR-forensic-recorder-is-working-on-excluded-Paths/m-p/217116#M8814</guid>
      <dc:creator>SWBW_Florian</dc:creator>
      <dc:date>2024-06-11T12:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: EFR: forensic recorder is working on excluded Paths</title>
      <link>https://community.checkpoint.com/t5/Endpoint/EFR-forensic-recorder-is-working-on-excluded-Paths/m-p/217138#M8815</link>
      <description>&lt;P&gt;As far as I know is not applicable to the E87.6x version. Note that the next release after E87.6x was in fact E88.00&lt;/P&gt;
&lt;P&gt;At least have the information for future reference since seems to be a relevant use case for you&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 15:35:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/EFR-forensic-recorder-is-working-on-excluded-Paths/m-p/217138#M8815</guid>
      <dc:creator>JonnyRabinowitz</dc:creator>
      <dc:date>2024-06-11T15:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: EFR: forensic recorder is working on excluded Paths</title>
      <link>https://community.checkpoint.com/t5/Endpoint/EFR-forensic-recorder-is-working-on-excluded-Paths/m-p/218322#M8825</link>
      <description>&lt;P&gt;OKay, thanks a lot. I just will go on and update the client. Lets see what happens&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you very much so far&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2024 06:56:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/EFR-forensic-recorder-is-working-on-excluded-Paths/m-p/218322#M8825</guid>
      <dc:creator>SWBW_Florian</dc:creator>
      <dc:date>2024-06-21T06:56:56Z</dc:date>
    </item>
  </channel>
</rss>

