Advanced Settings
Advanced Settings define the global monitoring parameters applied across audit reports and device policies in GuardWare INSIGHT. They function as the central control point for how monitoring is configured and enforced across the organisation.
These settings determine how INSIGHT operates on end-user devices, including the methods used to monitor the movement of sensitive data, the applications, URLs, and file extensions that are included or excluded from monitoring, and the configuration of communication between devices and the server.
Reference Table
The table below provides an overview of every Advanced Setting and what it does.
Controls the intervals, durations, timeouts, and bandwidth settings for uploading reports and downloading policies and commands.
Lists applications monitored for sensitive data uploads at the network level.
Lists IP addresses included or excluded from network-level monitoring.
Defines which applications have their SSL traffic monitored when network monitoring is used.
Defines which websites have their SSL traffic monitored using certificate common names.
Specifies applications where keystroke and copy/paste activity is monitored or excluded.
Specifies websites where keystroke and copy/paste activity is monitored or excluded.
Lists applications monitored at the network level using the LSP approach.
Lists client components and controls whether each is enabled or disabled.
Filters file upload monitoring by file extension type.
Lists applications monitored for sensitive data uploads at the file system level.
Lists applications monitored to provide full file path data for network monitoring.
Suppresses repeated incident alerts from specified applications at the file system level.
Lists browser applications monitored at the file system level to intercept file uploads on end-to-end encrypted websites.
Lists websites with end-to-end encryption where file system monitoring is required alongside network monitoring.
Create an Advanced Setting
Before configuring any monitoring parameters, an Advanced Setting policy must be created first. Once created, it starts in an Inactive state and needs to be configured before being activated and applied to devices.

Navigate to INSIGHT > Advanced Settings.
Click + New Advanced Setting.
Configure Policy Info
In the Policy Info tab, fill in the following fields and click Next:

Copy Settings From (Optional): Select an existing Advanced Setting to copy its configuration into this new one. Useful for duplicating a baseline policy instead of starting from scratch.
Setting Name: Enter a clear, identifiable name for the setting.
Description: Briefly describe what this setting is for, who it applies to, or how it differs from other settings.
Set as Default Setting (Optional): Marks this as the organisation-wide default. Only one default setting can be active at a time; it is automatically assigned to all newly created users and can be duplicated to create policy variations from a common baseline.
Configure Settings
Once created, the Advanced Setting starts in an Inactive state. Configure the required settings, then activate when ready to apply to devices. Each setting can be enabled or disabled. Disabling a setting reverts it to its default state, which disables the functionality associated with it.

Report Upload & Communication Settings
The intervals, durations, timeouts, and bandwidth settings that control the uploading of reports and downloading of policies and commands.

Click the checkbox to select the setting or click View Setting to open the configuration window.
Report Upload Settings: This setting controls how monitoring data is packaged and sent from client devices to the server.
Bulk Report Packet Size
(in Bytes)
The size of each data packet sent during a bulk report upload. Smaller packets result in more frequent sends; larger packets mean fewer, heavier transfers.
Report Interval
(in Min)
How often the client sends a report to the server. Lower values provide more real-time data; higher values reduce server load.
Bulk Report Time
(in Min)
The time window during which bulk reports are sent. Use this to schedule heavy uploads during off-peak hours.
Bulk Report Bandwidth
(in Bytes/Sec)
The maximum bandwidth the client can use when uploading bulk reports. Set to 0 for no limit.
Bulk Report Retry Interval
(in Min)
How long the client continues retrying a failed report upload before stopping.
Communication Settings: This setting controls connection behaviour, timeouts, polling frequency, and heartbeat signals between the client and server.
Connection Timeout
(in Sec)
How long the client waits for a server response before considering the connection failed.
Common Timeout
(in Sec)
A general timeout applied across standard communication operations.
Communication Interval
(in Min)
How frequently the client initiates a general communication cycle with the server.
Communication Interval Status
—
Indicates whether scheduled communication with the server is currently active.
Command Interval
(in Min)
How often the client checks for new commands from the server.
Setting Interval
(in Min)
How often settings are synchronized between client and server.
Setting Status Interval
—
Indicates whether automatic settings synchronization is currently active.
Client Status Interval
(in Min)
How often the client reports its status back to the server.
Client Command Interval Status
—
Indicates whether periodic command polling is currently active.
Applications Monitored at Network Level
List of applications that are monitored for sensitive data uploads at the network level. The proxy can only monitor applications that are explicitly on this list. If an application is not listed, its traffic will not be captured.
Use an exclude list with an empty list to apply monitoring to all applications. Using an include list for broad coverage is impractical and not recommended.

Click the checkbox to select the setting or click View Setting to open the configuration window.
Use the Search applications... to check if the application is already listed.
If found, select the checkbox next to it to enable monitoring.
If not listed, enter the application name with its extension (e.g.,
chrome.exe) in the Add Application field and click Add Application.Confirm the application appears in the list and is selected for monitoring.
IP Addresses Not Monitored at Network Level
List of IP addresses that are monitored, or not monitored, for sensitive data. This list is usually used to exclude IP addresses used by internal applications that are considered secure and do not need monitoring for the uploading of sensitive data.

Click the checkbox to select the setting or click View Setting to open the configuration window.
Enter the IP address in the Add IP field.
Click Add IP to add it to the list.
Confirm the IP address appears in the list.
Applications with Monitored SSL Traffic
List of applications whose SSL traffic is monitored for sensitive data uploads. This setting is tied to the network monitoring approach. If network monitoring is enabled, SSL traffic monitoring should also be enabled for the relevant applications. This section can be configured as either an include list or an exclude list, depending on the scope of monitoring required.

Click the checkbox to select the setting or click View Setting to open the configuration window.
Select the appropriate mode:
Include list: Only the listed applications will have their SSL traffic monitored.
Exclude list: All applications will have their SSL traffic monitored except those listed. Leave the list empty to monitor all applications.
Select the checkbox next to the application to add it to the list.
Websites with Monitored SSL Traffic
List of websites whose SSL traffic is monitored for sensitive data uploads. To monitor SSL traffic for specific websites only, add their URLs to the include list. To monitor all SSL traffic, use the Exclude List option and leave the list empty.

Click the checkbox to select the setting or click View Setting to open the configuration window.
Select the appropriate mode:
Include list: Only SSL traffic for the listed websites will be monitored.
Exclude list: All SSL traffic will be monitored except for the listed websites.
If your desired website is not on the list, enter the website URL (e.g.,
google.com) in the Add Website field, confirm it appears in the list, and select it.
Applications with Monitored Keystrokes and Copy/Paste
List of applications where keystrokes and copy/paste activity are monitored, or not monitored, for sensitive data. This is particularly useful for restricting monitoring in sensitive applications such as password managers or tools that handle confidential input.

Click the checkbox to select the setting or click View Setting to open the configuration window.
Select the appropriate mode:
Include list: Keystroke and copy/paste monitoring will apply only to the listed applications.
Exclude list: Keystroke and copy/paste monitoring will apply to all applications except those listed. Leave the list empty to monitor all applications.
Select the checkbox next to the application to add it to the list.
Websites with Monitored Keystrokes and Copy/Paste
List of websites where keystrokes and copy/paste activity are monitored, or not monitored, for sensitive data. This list is usually used to exclude banking or similar websites where users may type personal passwords.

Click the checkbox to select the setting or click View Setting to open the configuration window.
Select the appropriate mode:
Include list: Keystroke and copy/paste monitoring will apply only to the listed websites.
Exclude list: Keystroke and copy/paste monitoring will apply to all websites except those listed. Leave the list empty to monitor all websites.
Select the checkbox next to the website to add it to the list.
Applications Monitored at Network Level (LSP)
List of applications that are monitored for sensitive data uploads at the network level using the Layered Service Provider (LSP) approach. LSP is an alternative network interception method to WFP (Windows Filtering Platform).

Click the checkbox to select the setting or click View Setting to open the configuration window.
Enter the full file path to the application's DLL in the Add Winsock Exception field (e.g.,
C:\Windows\System32\wsock32.dll).Click Add New Exception to add it to the list.
Confirm the entry appears in the list.
Status of Client Components
List of client components, such as drivers, and whether they are enabled or not. Each component can be set to Default, Enable, or Disable individually.

Click the checkbox to select the setting or click View Setting to open the configuration window.
Review the components listed and adjust each toggle as required.
Proxy Options
Default
OFF / WFP / LSP
Controls the proxy mode used for network traffic interception. WFP (Windows Filtering Platform) and LSP (Layered Service Provider) are the two available interception methods.
Proxy Extension
Default
Enable / Disable
Enables or disables the proxy browser extension.
GW Scanner
Default
Enable / Disable
Monitors USB device insertions and tracks file-level changes on the system.
GW Dogfile
Default
Enable / Disable
Protects files within GuardWare directories from unauthorised modification or deletion.
Chat Docmon
Default
Enable / Disable
Monitors file usage by instant messaging applications at the file system level, including cloud-based services.
USB Monitor
Default
Enable / Disable
Tracks file transfers to USB devices connected to the system.
GWPG (Process Guard)
Default
Enable / Disable
Protects GuardWare processes from unauthorised termination. Operates as a kernel-level process for enhanced protection against tampering.
File Extensions Monitored at File System Level
List of file extensions that are monitored for sensitive data uploads at the file system level. Use this to focus monitoring on high-risk file types or to exclude low-risk types to reduce noise in reports.

Click the checkbox to select the setting or click View Setting to open the configuration window.
Select the appropriate mode:
Include list: Only uploads of the specified file extensions will be monitored.
Exclude list: All file uploads will be monitored except those with the specified extensions. Leave the list empty to monitor all file extensions.
Enter the file extension in the Add Extension field (e.g.,
pdf,xlsx,zip) and click Add Extension.Confirm the extension appears in the list.
Applications Monitored at File System Level
List of applications that are monitored for sensitive data uploads at the file system level.

Click the checkbox to select the setting or click View Setting to open the configuration window.
Select the checkbox next to the application to add it to the monitoring list.
If the application is not listed, enter the application name in the Add Application field and click Add Application.
Confirm the application appears in the list and is selected for monitoring.
Applications Monitored at File System Level to Provide File Path Information
List of applications monitored at the file system level to provide full file path information in network monitoring. Network monitoring captures the destination (the website) and the name of the uploaded file.

Click the checkbox to select the setting or click View Setting to open the configuration window.
Select the checkbox next to the application to add it to the monitoring list.
If the application is not listed, enter the application name in the Add Application field and click Add Application.
Confirm the application appears in the list and is selected for monitoring.
Applications Monitored at File System Level where Repeated Incidents are Ignored
List of applications monitored at the file system level where repeated incidents are ignored. This is usually used to prevent the over-reporting of file system activity that can occur when an application regularly uploads its internal files to its server, and those files contain content tagged as sensitive.

Click the checkbox to select the setting or click View Setting to open the configuration window.
Select the appropriate mode:
Include list: Repeated incident suppression will apply only to the listed applications.
Exclude list: Repeated incident suppression will apply to all applications except those listed.
Select the checkbox next to the application to add it to the list.
Applications Hosting Websites with End-to-End Encryption
List of browser applications to be monitored at the file system level in order to intercept file uploads on websites with end-to-end encryption. For websites implementing end-to-end encryption, it is not possible to intercept file uploads using network monitoring alone.
Where end-to-end encrypted websites are permitted, and there is a concern that files containing sensitive data may be uploaded, both file system monitoring (file paths and contents) and network monitoring (destinations) are required in order to produce reports containing URL and file path information for the uploaded sensitive data.

Click the checkbox to select the setting or click View Setting to open the configuration window.
Select the checkbox next to the application to add it to the monitoring list.
If the application is not listed, enter the application name in the Add Application field and click Add Application.
Confirm the application appears in the list and is selected for monitoring.
Websites with End-to-End Encryption
List of websites with end-to-end encryption. For websites implementing end-to-end encryption, it is not possible to intercept file uploads using network monitoring alone. Where end-to-end encrypted websites are permitted, and there is a concern that files containing sensitive data may be uploaded, both file system monitoring (file paths and contents) and network monitoring (destinations) are required in order to produce reports containing URL and file path information for the uploaded sensitive data.

Click the checkbox to select the setting or click View Setting to open the configuration window.
Select the appropriate mode:
Include list: Only the listed websites will be subject to end-to-end encryption file upload monitoring.
Exclude list: All websites will be monitored except those listed.
Enter the website URL or page title in the input field and click Add.
Confirm the entry appears in the list.
Review & Save
Scroll to the top of the page and click Review & Save. A summary of all configured settings will appear in the side panel.

Review the configurations. To make any changes, close the panel, update the relevant settings, and click Review & Save again.

Once satisfied, click Save to apply the configuration.
Manage Advanced Settings
After creating an Advanced Setting, it can be assigned to devices, edited, or deleted from the Advanced Settings list. Devices assigned to a deleted setting automatically revert to the default setting, which cannot itself be deleted. Bulk actions are also available for deleting multiple settings or reassigning devices from one setting to another.
Assign Devices
Navigate to INSIGHT > Advanced Settings.
Click Assign Devices next to the setting you want to assign to a device.

Select devices to assign the setting to, or deselect them to remove the setting.
Click Add to apply changes.
A device can have only one advanced setting assigned at a time.
Multiple devices can be assinged to an advanced setting.
When a new advanced setting is assigned to a device, the existing advanced setting is automatically removed and replaced.
Edit an Advanced Setting
Navigate to INSIGHT > Advanced Settings.
Click Edit next to the relevant setting.

Update the required fields and settings. The process follows the same steps as creating a new Advanced Setting.
Click Review & Save to review the changes.
Click Update to confirm changes.
Delete an Advanced Setting
Navigate to INSIGHT > Advanced Settings.
Click Delete next to the relevant setting.

Click Yes, Delete it! to confirm.
To delete settings in bulk, click the checkboxes next to the settings and select the Delete icon.
Last updated

