Managing interception settings in the Web Console

In the Web Console, you can configure system event interception in the policy properties (Application settings → General settings → System event interception).

The settings are applied only on devices where the operating system supports fanotify and the application is used in standard mode.

System event interception settings

Setting

Description

Interception mechanism

The system event interception mechanism used by the application:

  • Fanotify technology (default). If this option is selected, the application uses fanotify to intercept system events.
  • Updatable kernel module. If this option is selected, the application uses an updatable kernel module to intercept system events.

If the updatable kernel module fails to start

What the application does if the updatable kernel module fails to start:

  • Use fanotify (default). If this option is selected, the application switches to fanotify for system event interception.
  • Disable system event interception If the application does not use system event interception, real-time file scanning is not performed, and the protection level of the device is reduced.

This option is available if the Updatable kernel module interception mechanism is selected.

Page top