search cancel

File properties filtering still creates incidents or does not work

book

Article ID: 174450

calendar_today

Updated On:

Products

Data Loss Prevention Endpoint Prevent

Issue/Introduction

You set to ignore or monitor by file type in your agent configuration. You still receive incidents, or incidents are not created.

Cause

You may not have the file extension monitored or ignored based on what you want.

You may not have applied your agent configuration to an Agent Group. Agent configuration application is an important step that must be done.

Environment

  • Windows or macOS endpoint
  • Data Loss Prevention (DLP)
  • Agent Configuration

 

Resolution

Possible Reasons Channel Filters in Agent Configuration doesn't Work Properly

  1. Review what file types are monitored or ignored.
  2. You may have more than one Agent Configuration
  3. Check the order of monitoring or ignoring if it doesn't work correctly. The order does matter. 
  4. See if you use different filters for the endpoints that are located on or off the corporate network.

These suggestions apply to Application File Access, CD/DVD, Local Drive, and Cloud

Go to the Agent Configuration

Go to System > Agent > Agent Configuration then click on the "Channel Filters" tab.

You use the Filter by File Properties section to create and edit monitoring filters. Using this option lets you optimize performance and reduce false positives by filtering files before detection occurs. Based on the filters you set, the DLP Agent monitors or ignores data based on protocol, destination, file size, file type, or file path. Existing filters are listed in this section. The filters run in the order they appear in the list as determined by the Order column.

True file type filtering

The DLP Agent for Windows can filter specific types of files to monitor based on file signature data, also known as the true file type. File signature data, generally a short sequence of bytes at the beginning of the file, is used to identify or verify the file type. So, someone cannot change the extension trying to trick DLP from not monitoring a file type.


Note: Filtering on the DLP Agent for Mac occurs using the file extension only. True file type filtering is not supported for the DLP Agent for Mac.