- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi there,
today we observed issues with the Exclusions of the forensic recorder.
Were using a Backupsystem built by commvault. Harmony is very intense in working on those processes so they will fail and files got deleted during backups and general activity of the commvault software.
So i created Exclusions for our Backup-Server.
I excluded, at the end, the whole Software folder C:\Program Files\Commvault\ at:
Forensics: Quarantine Exlusions
Forensics: Anti Ransomware
I also added at Forensics: Monitoring
C:\Program Files\Commvault\*.exe
But i can still see with the ressource monitor of windows that the service EFR is working in those folders
Is the rule not accepted/working? Or ignored? Or buggy?
Because of the EFR Processes some of the jobs are falling into timeouts. This is a problem.
Can you give me a hint on how to configure the EFR in a right manner?
Thanks in advance
kind regards
Florian
This might be worth TAC case.
Where precisely did you try to define the exclusion?
I'd read this SK, which might shed some light on why this isn't working the way you expect: https://support.checkpoint.com/results/sk/sk128472
Hey,
Which client version are you using?
First the disclaimer ......... In general it best to have a full investigation of the issue; rather than just referring to a specific fix that would require an upgrade and may not address the issue. Also, not clear what version of client is being used.
However, since there was a recent fix released that seems very similar to this issue I will call it out and maybe relevant information for other people as well. It can be applicable to clients running E88.00 and later releases and there is a fix included in E88.31
See sk182277 for more information on this release. Specifically includes the following fix that may be related to this issue:
| AHTP-30676 | Some processes specified through the Monitoring and Exclusions action in the Policy are not fully excluded by the Forensics component from analysis as intended. |
were using client version 87.60 so maybe that fix wont suit here?
As far as I know is not applicable to the E87.6x version. Note that the next release after E87.6x was in fact E88.00
At least have the information for future reference since seems to be a relevant use case for you
OKay, thanks a lot. I just will go on and update the client. Lets see what happens
thank you very much so far
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 8 | |
| 4 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY