We use cookies to try and give you a better experience in Freshdesk.
You can learn more about what kind of cookies we use, why, and how from our Privacy policy. If you hate cookies, or are just on a diet, you can disable them altogether too. Just note that the Freshdesk service is pretty big on some cookies (we love the choco-chip ones), and some portions of Freshdesk may not work properly if you disable cookies.
We’ll also assume you agree to the way we use cookies and are ok with it as described in our Privacy policy, unless you choose to disable them altogether through your browser.
So the default is:
"Only monitor files that are included below
*.exe
*.sys"
But it appears Malwarebytes is constantly adding/removing a file from system32/drivers so I want to exclude that file. The radio for "include all except" and "monitory only" cannot have both selected, so do I simply create a 2nd "monitored folder" for the exclusion?
0 Votes
Ingmar Koecher posted almost 7 years ago Admin Best Answer
Yes, you would want to create a new event log package (or add one to an existing one) and then add the exclusion filter to that package. Just make sure the package is assigned correctly. We have a video that explains this in detail: https://www.youtube.com/watch?v=UQKaSToPrWo&t=77s. That video probably tells you more than you need to know - if you prefer a shorter tutorial then you can go here: https://www.eventsentry.com/support/tutorial/topic/include-exclude-filters/step/1.
Let me know if that helps.
0 Votes
5 Comments
Ingmar Koecher posted almost 7 years ago Admin
Glad you figured it out - yes it's insertion string.
0 Votes
Ingmar Koecher posted almost 7 years ago
Perfect! One last question, when adding the "content filters" (where it says "string (#1) matches") I am given three options, "wildcard," "insertion," or "regex" for "text match type." Which do I want?
EDIT: Nevermind, it's "insertion"
Thanks again!
0 Votes
Ingmar Koecher posted almost 7 years ago Admin Answer
Yes, you would want to create a new event log package (or add one to an existing one) and then add the exclusion filter to that package. Just make sure the package is assigned correctly. We have a video that explains this in detail: https://www.youtube.com/watch?v=UQKaSToPrWo&t=77s. That video probably tells you more than you need to know - if you prefer a shorter tutorial then you can go here: https://www.eventsentry.com/support/tutorial/topic/include-exclude-filters/step/1.
Let me know if that helps.
0 Votes
Ingmar Koecher posted almost 7 years ago
That sounds great! I have one dumb question though, where to navigate to set that exclusion filter?
0 Votes
Ingmar Koecher posted almost 7 years ago Admin
Adding a 2nd folder is not supported, since it would instruct EventSentry to monitor the same folder twice. The best approach to suppress these false alerts from Malwarebytes would be to create an exclude filter so that these alerts aren't forwarded to an email for example. The advantage of this approach is that the changes to the "drivers" directory still get recorded to the database.
I included a screenshot of what this exclusion filter could look like. You may have to change the 2nd content filter if the file that is being added is not mbamswissarmy.sys:
You can put this exclusion filter into any package that is assigned to the host where these alerts are generated, or you can create a new package.
I hope this helps, please let us know!
0 Votes
Login or Sign up to post a comment