After installing Deep Security Notifier on virtual machines (VMs) with agentless Deep Security, customer tried to test it using EICAR test file. The test file was prompty removed by the Anti-Malware module in Deep Security Manager, but there's no pop-up notification displayed on the Deep Security Notifier in VM.
On the Deep Security Notifier, it displays the agent status as "Unknown/Unreachable". There is also no event recorded in the Deep Security Notifier's Anti-Malware Events log.
Both VMware App Volumes and Deep Security Notifier fail to show notifications or events. The agentless Deep Security is working and is able to block the EICAR test file. The App Volumes agent is working fine as well. Only the Deep Security Notifier is not working properly.
Upon checking, when the App Volumes agent is enabled, the ds_notifier.vif change its location to C:\SVROOT\ProgramData\ds_notifier.vif. This causes the issue since Deep Security Virtual Appliance needs to access the file on path C:\ProgramData\ds_notifier.vif to be able to dump the information it needs to push in the user interface.
To resolve the issue, add the line "exclude_path=\ProgramData\ds_notifier.vif" in snapvol.cfg.