Hi,
we get a lot of "incidents" regarding "vssadmin.exe". The incidents are triggered by a task through our RMM.
The Task does on a regular basis:
- Delete a vss snapshot (yesterday)
- Create a vss snapshot (today)
The relevant part of the problem shows up here:
For sure, I won't create an exclusion for "vssadmin.exe".
Also excluding "C:\Windows\System32\vssadmin.exe" delete shadows /Shadow={184D3A2D-026A-4DEC-B1D4-0C8BF8BF3337} /quiet
won't be a good idea, because I had to use some kind of wildcard for "{184D3A2D-026A-4DEC-B1D4-0C8BF8BF3337}".
Any ideas, how to create some kind of exclusion for that case or how to handle these events?
Best regards,
Daniel