Just Published! Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

App Control Agent: What triggers USN Journal Cache Consistency check?

App Control Agent: What triggers USN Journal Cache Consistency check?

Environment

  • App Control Agent: All Versions

Question

  •  What triggers USN Journal Cache Consistency check?
  •  Cache Consisteny Check events reported to App Control Server  
Cache consistency check started Level[Full scan of new files] Options[USN Journal] Type[3] Flags[00000400] Number[1]

 

Answer

  • NTFS volumes have a feature called USN journaling
  • This feature logs file changes and allows a software such App Control Agent to detect file changes that have occurred while the software was not running
  • By default,  the App Control Agent is configured to run a cache consistency check whenever it detect these file changes
  • New volumes appearing that the Agent did not see before also count as a trigger to do the rescan.
  • This rescan can be disabled by setting the agent config_prop "usn_journal_flags" to "0"

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎05-02-2022
Views:
63
Contributors