IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

App Control: Is it normal to see System as the user that modified a file on a network drive?

App Control: Is it normal to see System as the user that modified a file on a network drive?

Environment

  • App Control (formerly CB Protection): All supported versions
  • Network file shares

Question

Is it normal behavior to see a file modified by 'System' if a file share is accessed over the network location file path and that file modified on the network drive?

Answer

Yes, files can be tracked on a network drive however there is no logged in user or agent on the network drive to track what user modified the file

Additional Notes

In order for an agent to track modifications to files the file has to be modified on a disk that has an agent and a logged in user

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎11-19-2020
Views:
277
Contributors