Issue ID: AV-04
Applies to: Datto AV
Environment: Windows, macOS
KB type: Reference
Overview
This article documents the supported syntax and known limitations for Datto AV policy exclusions. It also provides troubleshooting steps for exclusions that do not work as expected, including scenarios where exclusions stop working after a product update.
For general exclusion configuration, see Working with exclusions in your Datto AV policy.
Symptoms
- An exclusion that previously worked stops working after a product update.
- A wildcard exclusion does not behave as expected.
- An exclusion for a file without a file extension is rejected or ignored.
Supported Exclusion Syntax and Limits
- Exclusion types: File, folder, and process exclusions are supported.
- Wildcard support: Wildcards are supported for folders, file extensions, and filenames, but only at a single folder level. Recursive wildcards or multi-level folder wildcards are not supported.
- File exclusions: File exclusions must include a file extension (e.g., .exe, .dll). Files without extensions cannot be directly excluded.
- Folder exclusions: Folder exclusions require a trailing backslash and apply recursively to all files and subfolders within the specified folder.
- Process exclusions: Supported as documented in the Datto AV policy configuration.
For full syntax details, see Working with exclusions in your Datto AV policy.
Exclusion Persistence After Updates
- Exclusion persistence issues present in earlier versions have been resolved. Exclusions configured in the Datto AV policy now persist after product updates.
- If an exclusion appears to be missing after an update, verify the exclusion configuration and policy assignment.
Troubleshooting Steps
If an exclusion does not work as expected, follow these steps:
-
Verify exclusion type and syntax
- Identify whether the exclusion is for a file, folder, or process.
- Ensure the exclusion uses the correct syntax and includes a file extension if excluding a file.
- Reference: Working with exclusions in your Datto AV policy
-
Check policy configuration and assignment
- In the Datto EDR portal, navigate to the assigned policy.
- Confirm the exclusion is present, correctly formatted, and saved.
- Ensure the policy is assigned to the intended endpoint(s).
-
Validate policy application
- Confirm the endpoint has received the latest policy update via the AppSettings.json located in C:\ProgramData\DattoAV\Endpoint Protection SDK\settings\.
- Restart the Datto EDR service on the endpoint if necessary.
-
Review logs and alerts
- Check the endpoint logs for exclusion-related errors or warnings.
- Review any Datto AV alerts to determine if the exclusion was bypassed or ignored.
-
Files without extensions
- Direct exclusion of files without extensions is not supported.
- Workaround: Use a folder exclusion or submit the file for review as a false positive.
- Reference: Datto AV File Submission
-
Escalation
- If the exclusion is correctly configured and still does not take effect, collect the following:
- Exclusion rule details
- Product version
- Datto EDR and AV logs
- Reference Accessing agent log files
- Escalate to Datto Support with this information.
- Reference: EDR: Diagnosing AV exclusions that are not working
- If the exclusion is correctly configured and still does not take effect, collect the following:
Tips
- If an exclusion stops working after an update, confirm the policy assignment and review the exclusion configuration.
- For files without extensions, folder exclusions or file submission are required.
- For false positives after updates, consider using alert-only mode and submit affected files for review.
Reference: How to address false positives