Security Compliance
Disable the File Integrity Monitoring (FIM) driver in SEM
This article provides brief information and steps to disable the File Integrity Monitoring (FIM) driver. The FIM driver is installed and enabled during a SEM agent installation to a Windows machine. It allows the FIM connector to read and collect file auditing events from a Windows host. The FIM driver is disabled for troubleshooting purposes only. Contact your administrator to check for any security policies before performing the following steps.
First published date
Last published date
Overview
This article provides brief information and steps to disable the File Integrity Monitoring (FIM) driver.
The FIM driver is installed and enabled during a Security Event Manager (formerly Log & Event Manager) agent installation to a Windows machine. It allows the FIM connector to read and collect file auditing events from a Windows host.
The FIM driver is disabled for troubleshooting purposes only. Contact your administrator to check for any security policies before performing the following steps.
Product section
Resolution
Disable FIM driver from the SEM Console:
- Log into your SEM console.
- Go to Manage > Nodes.
- Select the agents of the FIM drivers to disable on startup.
To select multiple agents, press and hold the Ctrl key. - Click the FIM Driver Control drop-down and select Disable driver on agent startup.
In SEM versions 6.6 and newer, you can disable the FIM driver in the HTML5 SEM Events Console.
- In the SEM Events Console, click the Nodes tab.
- Under Refine Results, expand the Type tab, and then select the Agent check box.
- In the Agents list, select the agents of the FIM drivers to disable on startup.
- From the Commands drop-down list, select Disable FIM on agent machine startup.
Note: If only one agent is selected, use the More drop-down list.
The FIM driver should now be disabled from your SEM Flash console or SEM HTML5 console.
Disable FIM driver from the local machine:
- Open the Command Prompt (CMD) with administrator rights.
- Run the following command:
- 32-bit Windows - C:\Windows\System32\ContegoSPOP\FIM
- 64-bit Windows - C:\Windows\SysWOW64\ContegoSPOP\FIM
- Double-click the FIM uninstall script in the following location:
- 32-bit Windows - C:\Windows\System32\ContegoSPOP\FIM\uninstall_driver.bat
- 64-bit Windows - C:\Windows\SysWOW64\ContegoSPOP\FIM\uninstall_driver.bat
The FIM driver should now be disabled from your local machine.