search cancel

Auto-Protect can't detect EICAR test file on certain directories in linux machines

book

Article ID: 175661

calendar_today

Updated On:

Products

Cloud Workload Protection

Issue/Introduction

Customer is facing an issue where Auto-Protect can't detect EICAR test file in some directories until sisamdagent is restarted

1. Following are the directories reported by customer.

/root
/home/mars ( Mars is a directory created by customer by mkdir command )
/opt

2. Eicar gets detected under /tmp/ or /var locations. However, the locations mentioned by customer remains undetected.

3. Further restarting the sisamdagent agent, the file gets detected on accessing it.

Environment

Cloud Workload Protection

Cause

The fix will come as part of the next CWP refresh.

Resolution

The fix will come as part of the next CWP refresh.