Hi, we followed your advice and forwarded a false positive report to fp_reports@elastic.co but have not received any response. Pls advise:
As a result of this nonsense, Lurkit terminated our service contract and suffered losses. On what basis does it detect the virus?!
Hello and thank you for reaching out. Our team reviews false positive submissions on a monthly basis. While we don’t guarantee that we’ll take action on each request, if we do decide to take action and treat the detection as an FP, you can expect to see an update within a month.
If you encounter any FPs in your environment, you can create Endpoint Exceptions to resolve any alerts and avoid further alerts in the future. If you choose to go this route, make sure you create an Endpoint Exception, not a Rule Exception.
I see that file is signed. Exceptions can be made by signer, which will exclude all files signed by that entity.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.