DLP agent showing block pop up message when right click on any file on the local drive

book

Article ID: 160709

calendar_today

Updated On:

Products

Data Loss Prevention Endpoint Prevent

Issue/Introduction

DLP agent showing block pop up message when right click on any file on the local drive, even if the Local Drive scanning is unchecked.

Other Symptoms - every time the drive is mapped it will show scanning box even if the Network Shares is unchecked.

Obfuscated edpa_ext0 logs shows :-

 

Dim Detection Request Details :
 Process Id : 5164

 Process Path : \Device\HarddiskVolume1\Windows\explorer.exe
 Application Name : explorer.exe
 User : <username>
 Domain : <domain>
 Time Stamp : 09/08/2011 11:51:40
 Dim Event Type : File System


DIM File Detection Request Details :
 file: C:\Users\<username>\AppData\Local\Microsoft\Windows\Burn\Burn\desktop.ini
]

09/08/2011 11:51:40 |  2136 | INFO    | MessageLogger   | MESSAGETYPE_SCHEDULE_DETECTION    MESSAGESOURCE_DETECTION_CACHE  09/08/2011 11:51:40  [req#84 DetectionThreadPriority=NORMAL CrackingProcessPriority=NORMAL]

09/08/2011 11:51:40 |  2136 | INFO    | MessageLogger   | MESSAGETYPE_DETECTION_RESULT    MESSAGESOURCE_DETECTION  09/08/2011 11:51:40  [req#84 SUCCESS has incidents]

...

09/08/2011 11:51:40 |  2136 | INFO    | MessageLogger   | MESSAGETYPE_RESPONSE_POPUP    MESSAGESOURCE_POSTPROCESSOR  09/08/2011 11:51:40  [req#84 response#0]

09/08/2011 11:51:40 |  2136 | INFO    | MessageLogger   | MESSAGETYPE_DETECTION_RESPONSE    MESSAGESOURCE_POSTPROCESSOR  09/08/2011 11:51:40  [
Request Id #84 SUCCESS prevent
Scan Time : 31 ms]

09/08/2011 11:51:40 |  2136 | INFO    | MessageLogger   | MESSAGETYPE_DETECTION_REQUEST    MESSAGESOURCE_FILE_SYSTEM_CONNECTOR  09/08/2011 11:51:40  [
Request Id #91
Detection Request Details :
 Session Command : Single Request
 Request Type : Data In Motion Request

Resolution

Check On the Endpoint server if the following is added under Add Monitoring Filter

Enforce > System > Servers > Overview > {endpoint server} > Configure > Agent Monitoring

Ignore          CD/DVD, Local Drive               type = *

 

If the above filters are not added then add the following in the Add Monitoring Filter

 

 

 

Ignore          CD/DVD, Local Drive               type = *.ini