File System Monitoring

In this section:

General Information.

Managing Operation of the File System Monitor.

Setting the File System Monitor.

Problems with SpIDer Guard Operation.

General Information

Continuous monitoring of file system objects is performed by the file system monitor SpIDer Guard.

The Dr.Web for Linux graphical management interface allows to configure SpIDer Guard, namely:

Start and stop the file system monitor.

View component statistics and list of detected threats.

Configure the following parameters of the file system monitor:

Reaction to detected threats.

List of objects excluded from scanning.

Managing Operation of the File System Monitor

You can start and stop the file system monitor SpIDer Guard and view statistics on its operation on the special page of Dr.Web for Linux. To access the page, click SpIDer Guard on the main page.

Figure 13. SpIDer Guard management page

On the page for monitoring management, the following information is displayed:

State of the file system monitor SpIDer Guard (enabled or disabled) and details on errors if they occurred during the component operation.

File system monitoring statistics:

Average file scanning speed.

Number of detected and neutralized threats.

To enable monitoring, if disabled, click Enable. To disable monitoring, if enabled, click Disable.

To disable the file system monitor, the application must operate with elevated permissions. Refer to Managing Application Privileges section.

 

The option to enable and disable SpIDer Guard when Dr.Web for Linux is operating under the centralized protection server can be blocked if disabled by the server.

SpIDer Guard state (enabled or disabled) is shown with the indicator:

File system monitor SpIDer Guard is enabled and is protecting the file system.

File system monitor SpIDer Guard is not protecting the file system because either the user disabled the component, or an error occurred.

To close the page, go to another page by using the buttons in the pane.

The list of threats detected by SpIDer Guard in current Dr.Web for Linux session is displayed on the detected threats view page (available if at least one threat is detected).

Setting the File System Monitor

You can set how the file system monitor SpIDer Guard works in the settings window:

On the SpIDer Guard tab, specify reaction to detected threats.

On the Exclusions tab, specify objects to be excluded from monitoring.

For details on enabling the enhanced file monitoring mode by SpIDer Guard, refer to File Monitoring Modes.

Problems with SpIDer Guard Operation

If an error occurs in operation of SpIDer Guard, the management page displays the error message. To solve the problem, refer to the description of known errors in Appendix D.