You can add process exclusions to a real-time indicator detection policy assigned to all of your host endpoints or selected host sets using the Web UI or the API.
Note
Real-time monitoring process exclusions do not apply to processEvent and dnsLookupEvent for processes running on Windows endpoints. Real-time monitoring still records these events for processes running on Windows endpoints. NetworkEvent and processEvent are recorded on endpoints using Linux and process exclusions will exclude both of these event types.
Process exclusions are not supported on endpoints using the macOS.
This section covers the steps for adding process exclusions to your real-time indicator detection policy using the Web UI. See the Endpoint Security (HX) REST API Guide for information on using the API to manage your real-time event monitoring process exclusions.