File properties filtering still creates incidents or does not work
Last Updated April 25, 2019
You are set to ignore or monitor by file type in your agent configuration and you are still getting incidents or it is not creating incidents.
Windows or macOS endpoint
Data Loss Prevention (DLP)
You may not have the file extension monitored or ignored based on what you want.
You may not have applied your agent configuration to an Agent Group. This is an important step that must be done.
Possible Reasons Channel Filters in Agent Configuration is Not Working Properly
Review what file types are monitored or ignored.
You may have more than one Agent Configuration
Check the order of monitoring or ignoring if it is not working correctly. The order does matter.
See if you are using different filters for endpoints located on or off the corporate network.
These suggestions apply to Application File Access, CD/DVD, Local Drive, and Cloud
Go to the Agent Configuration
Go to System > Agent > Agent Configuration then click on the Channel Filters tab.
You use the Filter by File Properties section to create and edit monitoring filters. Using this option lets you optimize performance and reduce false positives by filtering files before detection occurs. Based on the filters you set, the DLP Agent monitors or ignores data based on protocol, destination, file size, file type, or file path. Existing filters are listed in this section. The filters run in the order they appear in the list as determined by the Order column.
True file type filtering
The DLP Agent for Windows can filter specific types of files to monitor based on file signature data, also known as the true file type. File signature data, generally a short sequence of bytes at the beginning of the file, is used to identify or verify the file type. So, someone cannot change the extension trying to trick DLP from not monitoring a file type.
Note: Filtering on the DLP Agent for Mac occurs using the file extension only; true file type filtering is not supported for the DLP Agent for Mac.
Subscribing will provide email updates when this Article is updated. Login is required to Subscribe