DLP agent showing block pop up message when right click on any file on the local drive
search cancel

DLP agent showing block pop up message when right click on any file on the local drive

book

Article ID: 160709

calendar_today

Updated On:

Products

Data Loss Prevention Endpoint Prevent

Issue/Introduction

DLP agent showing block pop up message when right click on any file on the local drive, even if the Local Drive scanning is unchecked.

Other Symptoms - every time the drive is mapped it will show scanning box even if the Network Shares is unchecked.

Obfuscated edpa_ext0 logs shows :-

 

Dim Detection Request Details :
 Process Id : 5164

 Process Path : \Device\HarddiskVolume1\Windows\explorer.exe
 Application Name : explorer.exe
 User : <username>
 Domain : <domain>
 Time Stamp : 09/08/2011 11:51:40
 Dim Event Type : File System


DIM File Detection Request Details :
 file: C:\Users\<username>\AppData\Local\Microsoft\Windows\Burn\Burn\desktop.ini
]

09/08/2011 11:51:40 |  2136 | INFO    | MessageLogger   | MESSAGETYPE_SCHEDULE_DETECTION    MESSAGESOURCE_DETECTION_CACHE  09/08/2011 11:51:40  [req#84 DetectionThreadPriority=NORMAL CrackingProcessPriority=NORMAL]

09/08/2011 11:51:40 |  2136 | INFO    | MessageLogger   | MESSAGETYPE_DETECTION_RESULT    MESSAGESOURCE_DETECTION  09/08/2011 11:51:40  [req#84 SUCCESS has incidents]

...

09/08/2011 11:51:40 |  2136 | INFO    | MessageLogger   | MESSAGETYPE_RESPONSE_POPUP    MESSAGESOURCE_POSTPROCESSOR  09/08/2011 11:51:40  [req#84 response#0]

09/08/2011 11:51:40 |  2136 | INFO    | MessageLogger   | MESSAGETYPE_DETECTION_RESPONSE    MESSAGESOURCE_POSTPROCESSOR  09/08/2011 11:51:40  [
Request Id #84 SUCCESS prevent
Scan Time : 31 ms]

09/08/2011 11:51:40 |  2136 | INFO    | MessageLogger   | MESSAGETYPE_DETECTION_REQUEST    MESSAGESOURCE_FILE_SYSTEM_CONNECTOR  09/08/2011 11:51:40  [
Request Id #91
Detection Request Details :
 Session Command : Single Request
 Request Type : Data In Motion Request

Resolution

Check On the Endpoint server if the following is added under Add Monitoring Filter

Enforce > System > Servers > Overview > {endpoint server} > Configure > Agent Monitoring

Ignore          CD/DVD, Local Drive               type = *

 

If the above filters are not added then add the following in the Add Monitoring Filter

 

 

 

Ignore          CD/DVD, Local Drive               type = *.ini