The Security Analytics rules are not being triggered when criteria for file name, file extension or file type is being met.
Security Analytics version 8.2.7 and earlier.
This is caused by a limitation with HTTP version 2 traffic and the classification engine that Security Analytics uses. HTTP version 1 traffic is indexed just fine and does not have this problem.
This is fixed in Security Analytics version 8.2.8.