What Is a "File Read-Write" Event?
Question
What is a "File Read-Write" event on the Endpoint Protector Server?
Answer
On the Endpoint Protector Server, a "File Read-Write" event monitors scenarios where files are accessed for both reading and writing, such as when editing a document. Administrators can set up alerts for these events to track and respond to such activities effectively.
Setting Up a "File Read-Write" Alert
- Navigate to Device Control Alerts in the Endpoint Protector console as root, Super Admin, or Device Control Admin.
- Click Create to start setting up a new alert.
- Configure the alert information:
- Event: Select File Read-Write from the drop-down menu.
- Administrators: Choose the administrators who should receive alert notifications.
- Alert Name: Provide a meaningful name for the alert.
- Specify device types and devices:
- Device Type: Choose the type of device (for example, USB, external hard drive) where you want the alert to be active.
- Device: Select the specific device(s) to which the alert should apply.
- Select monitored entities:
- Choose which groups, computers, or users should be monitored for this event.
- Click Save to finalize the alert setup.
Tracking Existing Alerts
- Navigate to Log Reports within the Reports and Analysis section.
- In Log Reports, go to Filters > Events.
- Select File Read-Write from the drop-down menu.
- Click Apply to view events that match your criteria.