Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Integrity Monitoring (IM) includes subdirectories in the generated baseline even if it is not selected

    • Updated:
    • 7 Jan 2015
    • Product/Version:
    • Deep Security 9.0
    • Platform:
    • VMware ESXi 5.1
    • VMware ESXi 5.5
    • Windows 2008 Enterprise
    • Windows 2008 Enterprise 64-bit
Summary
When customer creates Integrity Monitoring (IM) rule to control all files on a specified root directory, Deep Security Agent (DSA) generates baseline for all files from that root directory and all its subfolders even if the Include Sub Directories option is not selected. Below shows the rule setting for this case:
Include Sub Directories is not selected in the IM rule settings
Details
Public
If an Entity Set has no “include" or “exclude" tags, all entities below the hierarchical base value (if applicable) are included. An “exclude" tag without at least one (1) “include" tag is useless - nothing will be matched since there is no “include" tag. To address the issue:
Workaround:
As workaround, prevent subdirectories from being included to the baseline by putting an asterisk sign (*) to the Include Files With Names Like (One Per Line) field in the IM rule settings.
IM rule settings with “Include” tag
Solution:
This Patch enables DSA to match patterns in IM rules, which prevents IM to include subdirectory in the baseline even if subdirectory is not selected. For more information regarding DSM SP1 Patch 4, you may refer to the Readme file.
Premium
Internal
Rating:
Category:
Configure; Troubleshoot; Deploy; Install
Solution Id:
1107059
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support


To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.


Need More Help?

Create a technical support case if you need further support.