Antivirus Interference Detected

Description

This alert is triggered when Windows Defender actively quarantines or removes an item under a Relativity-related path (the Relativity installation directory, ProgramData\Relativity, or the Relativity temp storage directory) on a host within the current evaluation window, rather than merely being installed and running.

Resolution Guidance

Impact When Active

Windows Defender detecting and acting on an item (quarantine or removal) only causes a Relativity impact when the affected item is a file Relativity depends on - for example, a false-positive detection on a Relativity binary or script, or a genuine threat picked up during install, upgrade, or agent execution. In that case, the removed or quarantined file can cause missing-file errors, failed installs/upgrades, or broken functionality tied to that item.

This alert does not cover general antivirus scan overhead, slowness, file locks, or access-denied errors while a scan is in progress - those do not produce a Defender detection record and are not reflected in this metric. Only an actual threat detection and action counts; slowness alone is not a threat.

To resolve this alert, you can try:

  • Login to Kibana.
  • Click on the alert link in Relativity to navigate to the Antivirus Kibana dashboard.
  • Identify the affected host and the resource path involved from the dashboard's Antivirus Info table.
  • Look into the Antivirus saved search and dashboard in Kibana for additional detail on the affected resource path.
  • No configuration change is required to clear this alert, and there is nothing to exclude - no Relativity operation causes the detected threat, so excluding a Relativity path would not affect this alert. It reflects antivirus activity within the current evaluation window only, and it resolves on its own once that window passes: the alert clears after the next scraper run, within about 10 minutes.

Alert Details

Alert Condition Details

Name Value
Rule Type Elasticsearch query
Group Count (all)
Filter Query numeric_labels.relsvr_antivirus_interference_detected: 1 and labels.relsvr_antivirus_interference_resource_paths: (\Program Files\kCura Corporation or \ProgramData\Relativity or \AppData\Local\Relativity\TempStorage)
Threshold > 0
Time Window 10 min
Frequency 5 min

Alert Metric Details

Metric Name: relsvr.antivirus

Metric Description: Alert triggers when Windows Defender has actively interfered with a host (quarantine or removal) within the current evaluation window.

Metric Attributes:

Attribute Name Description
numeric_labels.relsvr_antivirus_interference_detected Whether antivirus interference was detected (0/1).
labels.relsvr_antivirus_interference_resource_paths The file path(s) involved in the antivirus interference, when available.
Feedback