The Customer reports that incidents are generated in a spontaneous way. Some times are generated during the dawning or when their leave for a moment the Endpoint and get back, they see the DLP blocking window.
In the snapshot appears that these incidents are generated as "Application File Access" when files are open from %programdata% and %appdata" when those paths are excluded in the Agent configuration.
Release : 16.0
The customer had removed the ignore rule from channel filters, so application file access was hitting on everything.
Once the channel filter was returned to default the problem was resolved.