Antivirus Interference Detected
Description
This alert is triggered when Windows Defender actively quarantines or removes an item under a Relativity-related path (the Relativity installation directory, ProgramData\Relativity, or the Relativity temp storage directory) on a host within the current evaluation window, rather than merely being installed and running.
Resolution Guidance
Impact When Active
Windows Defender detecting and acting on an item (quarantine or removal) only causes a Relativity impact when the affected item is a file Relativity depends on - for example, a false-positive detection on a Relativity binary or script, or a genuine threat picked up during install, upgrade, or agent execution. In that case, the removed or quarantined file can cause missing-file errors, failed installs/upgrades, or broken functionality tied to that item.
This alert does not cover general antivirus scan overhead, slowness, file locks, or access-denied errors while a scan is in progress - those do not produce a Defender detection record and are not reflected in this metric. Only an actual threat detection and action counts; slowness alone is not a threat.
To resolve this alert, you can try:
- Login to Kibana.
- Click on the alert link in Relativity to navigate to the Antivirus Kibana dashboard.
- Identify the affected host and the resource path involved from the dashboard's Antivirus Info table.
- Look into the Antivirus saved search and dashboard in Kibana for additional detail on the affected resource path.
- No configuration change is required to clear this alert, and there is nothing to exclude - no Relativity operation causes the detected threat, so excluding a Relativity path would not affect this alert. It reflects antivirus activity within the current evaluation window only, and it resolves on its own once that window passes: the alert clears after the next scraper run, within about 10 minutes.
Alert Details
Alert Condition Details
| Name | Value |
|---|---|
| Rule Type | Elasticsearch query |
| Group | Count (all) |
| Filter Query | numeric_labels.relsvr_antivirus_interference_detected: 1 and labels.relsvr_antivirus_interference_resource_paths: (\Program Files\kCura Corporation or \ProgramData\Relativity or \AppData\Local\Relativity\TempStorage) |
| Threshold | > 0 |
| Time Window | 10 min |
| Frequency | 5 min |
Alert Metric Details
Metric Name: relsvr.antivirus
Metric Description: Alert triggers when Windows Defender has actively interfered with a host (quarantine or removal) within the current evaluation window.
Metric Attributes:
| Attribute Name | Description |
|---|---|
| numeric_labels.relsvr_antivirus_interference_detected | Whether antivirus interference was detected (0/1). |
| labels.relsvr_antivirus_interference_resource_paths | The file path(s) involved in the antivirus interference, when available. |