You are viewing limited content. For full access, please sign in.

Question

Question

CrowdStrike & Laserfiche

asked on May 18, 2022

Hi All,

 

One of our customers is looking at implementing CrowdStrike across their network and have asked if there are any specific configuration points needed for Laserfiche, or any recommendations from Laserfiche on what should be configured within the AV solution (white listing etc.).

 

Does anyone have any experience of using CrowdStrike & On Premise Laserfiche, or have any meaningful suggestions?

 

Cheers!

Chris

0 0

Answer

SELECTED ANSWER
replied on May 18, 2022 Show version history

CrowdStrike is great, your customer made a good choice.

I wrote this in response to a similar question we got internally a few months ago. You may consider it semi-official guidance:

Customers should not configure AV exclusion rules for Laserfiche except in the following three circumstances:

  1. There is a specific Laserfiche issue in the environment reasonably believed to have an AV component.
    In this scenario we recommend (very) temporarily disabling AV to test whether doing so resolves the issue, and if so, re-enabling AV and putting in a targeted exclusion for the relevant area.
  2. During migrations where you’re moving large volumes of known good files. AV often becomes a primary bottleneck to bulk file transfers and downloads and it’s appropriate to disable it or add relevant exclusions until the file/volume migration is complete.
  3. In ongoing high-volume, performance sensitive scenarios involving Workflow and Quick Fields, it may be appropriate to exclude the Workflow and Quick Fields working directories for performance reasons.

Modern endpoint security (“AV”) solutions like CrowdStrike are much lighter weight with significantly lower performance impacts than antivirus agents of the past. These rely more on behavior-based heuristics for malware detection than traditional “match file signature against malware signature database” methods. That isn't to say that the modern endpoint security solutions can't cause issues, but rather that they seem to do so less frequently, and that customers should not preemptively add AV exclusions.

Cheers,
Sam

3 0
replied on May 19, 2022

Thanks Sam!

1 0

Replies

replied on May 19, 2022 Show version history

We are also running crowdstrike on our Laserfiche environment for the past 3 years. I don't have any special exclusions for any of our servers.


Crowdstrike is only looking for irregular activity. You should be good.

2 0
You are not allowed to follow up in this post.

Sign in to reply to this post.