The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

excludedPaths Key

Prev Next

The excludedPaths key specifies the files and folders to be excluded from monitoring of file write events for real-time indicator detection global exclusion policy. This policy must be enabled using the Web UI. If the policy is not enabled, this setting is ignored.

Use quotation marks (") to specify the file or folders you want excluded from real-time indicator detection and commas to separate each entry. Enclose the full list of files and folders in brackets ([]). For example:

"excludedPaths": [
    "%WINDIR%\\system32\\",
    "%ProgramData%\\FireEye\\xagt\\events.*"
]

Change this setting using one of the following methods: