Support Center > Search Results > SecureKnowledge Details
How to disable SandBlast Agent Data Collection
Solution
SandBlast Agent Data Collection sends anonymized incident related data to the CheckPoint ThreatCloud. This data helps improve protections for all our customers. The data currently being sent may include:
  • Anonymized Forensic Reports
  • Memory Dumps of Malicious/Compromised Processes (currently disabled)
  • Malicious Files (currently disabled)
To disable Data Collection please do the following:
  1. Open SmartEndpoint console.

  2. Go to the Policy tab.

  3. Open the SandBlast Agent Forensics, Remediation And Anti-Ransomware policy.

  4. Edit the Monitoring and Exclusions action.

  5. Click on Add location.

  6. Choose Process.

  7. Add the following text to the Process name test box:

    <DcPolicy enabled="false" xmlns="http://schema.checkpoint.com/policy/v1/"></DcPolicy> 

  8. Click "OK".

  9. Save and Install Policy.

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Give us Feedback
Please rate this document
[1=Worst,5=Best]
Comment