- CheckMates
- :
- Products
- :
- Harmony
- :
- Endpoint
- :
- Re: EFR: forensic recorder is working on excluded ...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
EFR: forensic recorder is working on excluded Paths
Hi there,
today we observed issues with the Exclusions of the forensic recorder.
Were using a Backupsystem built by commvault. Harmony is very intense in working on those processes so they will fail and files got deleted during backups and general activity of the commvault software.
So i created Exclusions for our Backup-Server.
I excluded, at the end, the whole Software folder C:\Program Files\Commvault\ at:
Forensics: Quarantine Exlusions
Forensics: Anti Ransomware
I also added at Forensics: Monitoring
C:\Program Files\Commvault\*.exe
But i can still see with the ressource monitor of windows that the service EFR is working in those folders
Is the rule not accepted/working? Or ignored? Or buggy?
Because of the EFR Processes some of the jobs are falling into timeouts. This is a problem.
Can you give me a hint on how to configure the EFR in a right manner?
Thanks in advance
kind regards
Florian
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This might be worth TAC case.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Where precisely did you try to define the exclusion?
I'd read this SK, which might shed some light on why this isn't working the way you expect: https://support.checkpoint.com/results/sk/sk128472
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey,
Which client version are you using?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
First the disclaimer ......... In general it best to have a full investigation of the issue; rather than just referring to a specific fix that would require an upgrade and may not address the issue. Also, not clear what version of client is being used.
However, since there was a recent fix released that seems very similar to this issue I will call it out and maybe relevant information for other people as well. It can be applicable to clients running E88.00 and later releases and there is a fix included in E88.31
See sk182277 for more information on this release. Specifically includes the following fix that may be related to this issue:
AHTP-30676 | Some processes specified through the Monitoring and Exclusions action in the Policy are not fully excluded by the Forensics component from analysis as intended. |
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
were using client version 87.60 so maybe that fix wont suit here?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As far as I know is not applicable to the E87.6x version. Note that the next release after E87.6x was in fact E88.00
At least have the information for future reference since seems to be a relevant use case for you
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
OKay, thanks a lot. I just will go on and update the client. Lets see what happens
thank you very much so far
