Hi,
The client is asking us if they can fully mirror C:\Datacap directory with a secondary environment.
They say if any new file is created in C:\Datacap, it will always be detected as a suspicious activity.
While their Datacap applications' batch and product log files are in a different location and application files won't change in production,
I am afraid there may be product files that may be created temporarily during Datacap and Rulerunner server operation.
I don't want these files to be detected and reported as illicit activities.
Here are some that I know. Does anyone know if mirroring of C:\Datacap is feasible or a list of all files that may be updated/created?
<Files updated/created in daily production>
- C:\Datacap\Taskmaster\Rulerunner.xmlback is updated when Rulerunner is run/stopped.
<Files updated/created in periodic maintenance> *These files won't be created unless someone launches the tool.
- C:\Datacap\RRS\collection.xml is updated when Datacap Studio is opened/closed.
- C:\Datacap\<App>\dco_<App>\rules\collection.xml and dumpns.xml are updated when Datacap Studio is opened/closed.
- C:\Datacap\<App>\<App>.app.lock is created when Datacap Application is launched.
------------------------------
dsakai
------------------------------