Block response rule does not appear every time the policy is getting violated.
Last Updated May 16, 2019
Block response rule does not appear every time the policy is getting violated. User is testing it by trying to copy a confidential data to USB every 2-3 seconds. Although they are getting the incident for every violation.
It is working by design. It's taking the cache from the previous value.
There is a setting under Advanced agent setting of Agent configuration:
Details: Maximum time, in seconds, in between two file operations to be considered as a single transaction. Default value is 10 seconds. Please make it to 1, save and apply changes so that the new configuration takes affect.
Imported Document ID: TECH219529
Subscribing will provide email updates when this Article is updated. Login is required to Subscribe