File Activity Monitor-Policy

File Activity Monitor (FAM) monitors file activities on selected drives and helps detect unauthorized or suspicious changes to files. You can configure the file activities to monitor and exclude specific file extensions and folder paths from monitoring.

Supported operating systems: Windows and Mac

Configure File Activity Monitor

To configure File Activity Monitor:

  1. Go to Policy > Policy Settings and select File Activity Monitor.
  2. Turn on File Activity Monitor.
  3. Under Select location and events to monitor within the drives, select the drives and activities you want to monitor.

Configure monitored locations and activities

You can configure monitoring for the following locations:

Location Copy Delete Rename Extension Change
Removable Drive ✓ ✓ ✓ ✓
Local Drive ✓ ✓ ✓ ✓
Network Drive ✓ ✓ ✓ ✓

Select the required activities for each location.

Note:

  • Activities on network drives, file renaming, and file copying on local drives are monitored only on Windows endpoints.
  • When you select Rename for a location, the Extension Change checkbox is automatically selected because renaming a file can also change its file extension.

Configure File Extension Exclusions

Use Exclude File Extensions to prevent specific file types from being monitored.

By default, Use from Configurations > File Activity Monitor is selected. When selected, the exclusion list configured under Configurations > File Activity Monitor is used for the policy.

To configure exclusions specific to the policy:

  1. Clear Use from Configurations > File Activity Monitor.
  2. Enter the file extension without a dot. For example, xml, html, or zip.
  3. Click Add.
  4. To remove an extension, select it and click Delete.

Configure Folder Exclusions

Use Exclude Folders to exclude specific folder paths from monitoring.

By default, Use from Configurations > File Activity Monitor is selected. When selected, the exclusion list configured under Configurations > File Activity Monitor is used for the policy.

To configure exclusions specific to the policy:

  1. Clear Use from Configurations > File Activity Monitor.
  2. Enter the folder path in Folder Path.
  3. Click Add.
  4. To remove a folder, select it and click Delete.

For example:

  • Windows: C:\Seqrite Endpoint Protection
  • Mac: /Users/Admin/ExcludeList

For Windows, environment variables such as %Windir% can also be used.

Important: If you add custom extensions or folders and then select Use from Configurations > File Activity Monitor, the custom entries in the policy are overwritten by the exclusions configured under Configurations > File Activity Monitor.

Save the Policy

Click Save Policy to apply the File Activity Monitor settings.

Manage exclusions from Configurations

You can also maintain the common exclusion lists from Configurations > File Activity Monitor. When Use from Configurations > File Activity Monitor is selected in a policy, changes made to these lists are reflected in the respective policies.

View File Activity

File activity data can be viewed through the relevant reports under Reports.

Note:

  • FAM captures both the source and destination file paths whenever a file is copied or moved between Network, Local, or Removable drive locations, regardless of the source and target location combination.
  • FAM does not capture file copy activities performed within the same local system, specifically when a file is copied from one Local drive location to same or another local drive location.
  • In the FAM report, the captured source path is displayed in the From field.
Was this page helpful?