excludedPaths Key

Prev Next

The excludedPaths key specifies the files and folders to be excluded from monitoring of file write events for real-time indicator detection global exclusion policy. This policy must be enabled using the Web UI. If the policy is not enabled, this setting is ignored.

Use quotation marks (") to specify the file or folders you want excluded from real-time indicator detection and commas to separate each entry. Enclose the full list of files and folders in brackets ([]). For example:

"excludedPaths": [
    "%WINDIR%\\system32\\",
    "%ProgramData%\\FireEye\\xagt\\events.*"
]

Change this setting using one of the following methods: