File Activity Monitor (FAM) monitors file activities on selected drives and helps detect unauthorized or suspicious changes to files. You can configure the file activities to monitor and exclude specific file extensions and folder paths from monitoring.
Supported operating systems: Windows and Mac
Configure File Activity Monitor
To configure File Activity Monitor:
- Go to Policy > Policy Settings and select File Activity Monitor.
- Turn on File Activity Monitor.
- Under Select location and events to monitor within the drives, select the drives and activities you want to monitor.
Configure monitored locations and activities
You can configure monitoring for the following locations:
| Location | Copy | Delete | Rename | Extension Change |
|---|---|---|---|---|
| Removable Drive | ✓ | ✓ | ✓ | ✓ |
| Local Drive | ✓ | ✓ | ✓ | ✓ |
| Network Drive | ✓ | ✓ | ✓ | ✓ |
Select the required activities for each location.
Note:
- Activities on network drives, file renaming, and file copying on local drives are monitored only on Windows endpoints.
- When you select Rename for a location, the Extension Change checkbox is automatically selected because renaming a file can also change its file extension.
Configure File Extension Exclusions
Use Exclude File Extensions to prevent specific file types from being monitored.
By default, Use from Configurations > File Activity Monitor is selected. When selected, the exclusion list configured under Configurations > File Activity Monitor is used for the policy.
To configure exclusions specific to the policy:
- Clear Use from Configurations > File Activity Monitor.
- Enter the file extension without a dot. For example,
xml,html, orzip. - Click Add.
- To remove an extension, select it and click Delete.
Configure Folder Exclusions
Use Exclude Folders to exclude specific folder paths from monitoring.
By default, Use from Configurations > File Activity Monitor is selected. When selected, the exclusion list configured under Configurations > File Activity Monitor is used for the policy.
To configure exclusions specific to the policy:
- Clear Use from Configurations > File Activity Monitor.
- Enter the folder path in Folder Path.
- Click Add.
- To remove a folder, select it and click Delete.
For example:
- Windows:
C:\Seqrite Endpoint Protection - Mac:
/Users/Admin/ExcludeList
For Windows, environment variables such as %Windir% can also be used.
Important: If you add custom extensions or folders and then select Use from Configurations > File Activity Monitor, the custom entries in the policy are overwritten by the exclusions configured under Configurations > File Activity Monitor.
Save the Policy
Click Save Policy to apply the File Activity Monitor settings.
Manage exclusions from Configurations
You can also maintain the common exclusion lists from Configurations > File Activity Monitor. When Use from Configurations > File Activity Monitor is selected in a policy, changes made to these lists are reflected in the respective policies.
View File Activity
File activity data can be viewed through the relevant reports under Reports.
Note:
- FAM captures both the source and destination file paths whenever a file is copied or moved between Network, Local, or Removable drive locations, regardless of the source and target location combination.
- FAM does not capture file copy activities performed within the same local system, specifically when a file is copied from one Local drive location to same or another local drive location.
- In the FAM report, the captured source path is displayed in the From field.