Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

EDR: AV Exclusion Directories for Cluster Servers

EDR: AV Exclusion Directories for Cluster Servers

Environment

  • EDR server: All versions

Question

What path should be excluded from anti-virus (AV) applications running on EDR Servers?

Answer

Exclude the data directories on EDR servers (primary and secondary nodes in a cluster). To confirm the directory run this command in terminal:
grep DatastoreRootDir /etc/cb/cb.conf
 Default directory:
/var/cb/data

Additional Notes

  • Make sure to use the directory set in cb.conf. At cbinit the data directory might have been changed
  • Exclusions are necessary to avoid degradation in performance
  • Exclusions also avoid corruption of the Postgres and Solr databases
  • If performance degradation is seen in the environment, disabling the AV application should be the first attempt in troubleshooting

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎12-07-2018
Views:
1741
Contributors