How to whitelist or exclude an application from DLP Endpoint agents
Last Updated June 27, 2019
With Application Monitoring enabled, Symantec Data Loss Prevention (DLP) Endpoint Agent attempts to hook in and monitor any application. Certain applications may perform poorly with this monitoring enabled. In that case, Administrators may need to whitelist the application.
From the online help regarding application monitoring : By default, DLP Agents monitors Clipboard, print, network (HTTP and FTP), and file system (removable disc, local drive, and network share) activity on all applications. You can add applications when you want DLP Agents to monitor files that applications open or read. You can also add applications when you want to prevent Symantec Data Loss Prevention from monitoring the application.
Whitelist Endpoint Application :
From the Enforce console select System > Agents >Application Monitoring.
Select the application to white list. If it is not listed, click on "add application" and provide at least one of the required application binaries. Note: DLP attempts to validate every field populated. We recommend using as few as fields as needed. If the whitelist seems to fail, try changing which required field is populated or removing one of the other fields.
Uncheck all of the detection channels under the "Application Monitoring Configuration."
Click on save and verify the application in the list of monitoring activities is unchecked.
After making these changes, test the whitelisted application to see if the issue is resolved.
Note that on occasion it may be nessessary to make changes and update the agent configuration for the new application monitor.
To ignore macOS applications from being monitored:
Record the application name and the binary name of the application you want Symantec Data Loss Prevention to ignore. To obtain this information, open the application on a Mac endpoint and locate the required information on the Activity Monitor screen.
Go to System > Agents > Application Monitoring.
Click Add Application.
Enter the application name in the Name field.
Enter the binary name in the Binary Name field.
Select Generic in the Application Type list. You do not make any other selections.
Leave all other selections disabled.
Save your changes.
Symantec Data Loss Prevention agent will need to check in to update before the changes will be effective.
Imported Document ID: TECH220322
Subscribing will provide email updates when this Article is updated. Login is required to Subscribe