File Monitor Settings Window
The File Monitor Settings window provides global settings for managing log retention, the ability to disable office file filtering, inherited permissions for parent object changes, and AD accounts and file system activity processes for Threat Prevention file monitoring and blocking policies.
Step 1 – Click Configuration > File Monitor Settings on the menu; the File Monitor Settings window opens. Only Threat Prevention administrators can access this window.

Step 2 – Enable or disable the following options:
- Logs retention period, days – Log retention period for activity logs (TSV files) created by the Threat Prevention Agent for Windows servers or by the Activity Monitor Agent for NAS devices and then read by the Threat Prevention Agent. This doesn't affect File System Access Analyzer event types. The Threat Prevention Agent reads logs in real time, retains them for a set number of days, and then automatically deletes them. This setting configures the log retention period for all enabled policies using the File System Changes and/or File System Lockdown event types. By default, it is set to 10 days.
- Microsoft Office temporary files filtering – Global setting that is checked by default. If checked, the Threat Prevention Agent doesn't monitor temporary files associated with Microsoft Office operations, such as copying and pasting. When unchecked, the Threat Prevention Agent monitors all temporary files associated with Microsoft Office operations.
- FS inherited permissions filtering – Reports separate events for the parent object and each child object. When checked, the system reports only an event for the parent object.
- Exclude selected accounts – When checked, the user-supplied list of AD user and group names as well as well-known SIDs for built-in users/groups are excluded from file system monitoring and blocking policies at the global level. See the Select Local Processes to Exclude topic to specify accounts.
- Exclude selected processes – When checked, the user-supplied list of processes are excluded from the file system monitoring and blocking policies at the global level. See the Select Local Processes to Exclude topic to specify processes.
- Include Folder read / list operations – When checked, all list/read folder operations are included in the reporting for file system monitoring and blocking at the global level.
- Ignore SYSTEM account for NTDS.DIT file – When checked, a File System monitoring policy won't report SYSTEM account access to the .dit file, and a File System blocking policy won't block it. Backup programs often use the SYSTEM account to access the .dit file, and you may not want to report on or block such activity.
Step 3 – Click Update to save your changes.
Select Accounts to Exclude from Collections
A collection is a list of SIDs for built-in users/groups that is excluded for all File System activity. You can add more accounts to this collection.
Step 1 – Click Configuration > File Monitor Settings on the menu to launch the File Monitor Settings window.
Step 2 – Check the Exclude selected accounts checkbox and then click accounts. The Edit Collection window opens.

Step 3 – Use the Add (+) button to open the Select Active Directory Perpetrators Window to browse for and select AD accounts.
Step 4 – Click OK to save your changes.
Step 5 – Click Update on the File Monitor Settings window.
The system globally excludes any accounts added to the list from File System activity.
If the Exclude selected processes option is checked, any file activity generated by the processes added will have their File System activity ignored.
Select Local Processes to Exclude
Step 1 – Click Configuration > File Monitor Settings on the menu to launch the File Monitor Settings window.
Step 2 – Check the Exclude selected processes checkbox and then click processes. The Edit Collection window opens.
Step 3 – Use the Items textbox to enter process names. You must enter a process name exactly as is; for example, as it appears on the Details tab of Windows Task Manager.
Step 4 – Click OK to save your changes.
Step 5 – Click Update on the File Monitor Settings window.
The system won't report File System activity for any processes added to the list.