To add process exclusions for all host endpoints:
Log in to the Web UI as an administrator.
From the Admin menu, select Policiesto access the Policies page.
From the Policies table, select the Agent Default Policy and click the policy link to access the Edit Policy page.
Select the Real-Time Indicator Detection tab.
Verify that the Real-Time Indicator Detection ON/OFF switch is set to ON.
From the Exclude Processes from Real-Time Indicator Detection section, specify the full path of the executable file you want to exclude from real-time event monitoring in the Exclude Processes from Real-Time Indicator Detection field. You can specify the absolute file path or use Windows System variables to define the executable file path.
For example, adding
C:\windows\system32\notepad.exeor%windir%\system32\notepad.exeto the process exclusion list will excludenotepad.exefrom real-time event monitoring. The executable file path is not case sensitive..png)
Click Add.
Click Save.