# ESET File Security Quarantined .dim Files

**URL:** <https://discuss.elastic.co/t/eset-file-security-quarantined-dim-files/95258>\
**Category:** Elasticsearch\
**Created:** [August 1, 2017, 12:59am UTC](https://discuss.elastic.co/t/eset-file-security-quarantined-dim-files/95258 "2017-08-01T00:59:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mhasanbulli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mhasanbulli/32/20653_2.png) [@mhasanbulli](https://discuss.elastic.co/u/mhasanbulli)\
**Post date:** [August 1, 2017, 12:59am UTC](https://discuss.elastic.co/t/eset-file-security-quarantined-dim-files/95258/1 "2017-08-01T00:59:58Z")

</div>

Hello,

I have set up a local Elasticsearch instance with two nodes. I have Logstash sending documents every 15 minutes. Today one of our IT members warned me that there are some "viruses" on the Windows server I was given. When I checked 8 .dim files in the indices of one of the nodes have been identified as "a variant of leronim.512 virus". I have searched for a similar post on the discussion forums but it seems like there aren't any topics related with ESET. Below is a screenshot from the virus protection.

 ![ESET File Security Quarantined .dim Files](https://us1.discourse-cdn.com/elastic/original/3X/c/5/c5e35f98258f7d829ae88ef5e5cd461c935da940.png)

Has anyone seen a similar behaviour?

Cheers.

Edit: I know they are not viruses. Hence, I used quotation marks.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 1, 2017, 1:26am UTC](https://discuss.elastic.co/t/eset-file-security-quarantined-dim-files/95258/2 "2017-08-01T01:26:54Z")

</div>

This is a file that lucene creates, it's not a virus.

See [https://lucene.apache.org/core/6\_0\_1/core/org/apache/lucene/codecs/lucene60/package-summary.html](https://lucene.apache.org/core/6_0_1/core/org/apache/lucene/codecs/lucene60/package-summary.html)

---

<div class="post-metadata">

**Author:** ![mhasanbulli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mhasanbulli/32/20653_2.png) [@mhasanbulli](https://discuss.elastic.co/u/mhasanbulli)\
**Post date:** [August 1, 2017, 1:42am UTC](https://discuss.elastic.co/t/eset-file-security-quarantined-dim-files/95258/3 "2017-08-01T01:42:47Z")

</div>

> [@warkolm](#):
>
> This is a file that lucene creates, it’s not a virus.
> 
> See [org.apache.lucene.codecs.lucene60 (Lucene 6.0.1 API)](https://lucene.apache.org/core/6_0_1/core/org/apache/lucene/codecs/lucene60/package-summary.html)

Thanks for the reference @warkolm. I understand and knew they are not viruses. I think I did not phrase my question clearly. I was just wondering why ESET is marking them as viruses and if anyone came across a similar situation.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 1, 2017, 3:44am UTC](https://discuss.elastic.co/t/eset-file-security-quarantined-dim-files/95258/4 "2017-08-01T03:44:43Z")

</div>

You'd have to ask the vendor of the product.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 29, 2017, 3:44am UTC](https://discuss.elastic.co/t/eset-file-security-quarantined-dim-files/95258/5 "2017-08-29T03:44:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
