droezel 0 Posted September 27, 2018 Share Posted September 27, 2018 We're test driving Enterprise Inspector and at the moment I have more than 250 clients sending events to EEI, off course there's a lot of noise and I'm adding exclusions for normal application behaviour. I'm noticing that a lot of my exclusions do not work and the events that I want to exclude are just showing up again. Example exclusion for Process from SysWOW64 started by unpopular process [a0416] And still the event keeps showing up as warning: The signer and computernames match up, so I don't see any reason why... Any way to troubleshoot this? Link to comment Share on other sites More sharing options...
ESET Staff Damian K 2 Posted September 28, 2018 ESET Staff Share Posted September 28, 2018 Thank you for reporting the problem. It turned out that we have a bug, which blocks this from working correctly. The bug will be fixed in the next release. As a workaround, you can mark globalzpo.exe as safe in Executables View. This should silence this rule. Link to comment Share on other sites More sharing options...
Recommended Posts