Why is Real Time Processing not detecting new files on an SMB share?
Check your version:
This article applies to all MetaDefender Storage Security releases deployed on Windows or Linux systems.
Overview
Real Time Processing (RTP) on SMB shares is designed to automatically detect and scan new files as they arrive on the share. In some environments, files copied into the share are never picked up by RTP, even though On Demand and Scheduled scans against the same share work correctly and the logs show no errors. This article explains why this happens and how to configure MetaDefender Storage Security to detect these files.
Cause
Polling based RTP on SMB shares detects new files by their LastModifiedDate, not by the time they arrive on the share. Most copy tools preserve a file's original modified timestamp during a copy, so a copied file whose modified date is older than the job's discovery start date is never classified as new and is never picked up, even though On Demand and Scheduled scans find it since they enumerate the entire share. No errors appear in the logs because nothing is failing, the file is simply not considered new.
You can check a file's modified date as follows:
Windows: In File Explorer, right-click the file, select Properties, and check the Modified date on the General tab. You can also view the Date modified column directly in File Explorer.
A file's Modified date shown in the file's Properties on a Windows system
Linux: Run
ls -l <filename>to see the modification time, orstat <filename>and check the Modify field for the full timestamp.
A file's modified date shown in the output of ls -l on Linux.
Additional Configuration
This setting changes how the SMB discovery service handles Real Time Processing so that files are picked up based on their presence on the share rather than their LastModifiedDate. The same configuration line applies to both Windows and Linux deployments. To make RTP detect files on SMB shares regardless of their modified timestamps, add the following line to the customer.env file:
DISCOVERY_SERVICE_SMB_RTP_HANDLING=1
On Linux:
Open
/etc/mdss/customer.envin a text editorAdd the line above (if the parameter already exists, edit its value)
Save the file
Restart the application by running the following command in a terminal:
On Windows:
Open
C:\Program Files\OPSWAT\MetaDefender Storage Security\config\customer.envin a text editorAdd the line above (if the parameter already exists, edit its value)
Save the file
Restart the application by running the following commands in PowerShell as Administrator:
Support: If you have questions, concerns or want to report issues regarding MetaDefender Storage Security, please open a Support Case with the OPSWAT team via phone, online chat or form, or feel free to ask the community on our OPSWAT Expert Forum.