I have a Centos 7 system running Samba 4 and Sophos Anti virus for Linux.
When a large file is downloaded directly on the samba folder from a Windows client, Sophos generates tens (or hundreds, if I download a very large file) of equal messages similar to the one bellow:
An error classified as '1/0x4021a' was detected in the file
'/folder/file.zip-{ae54f372-8e1c-4c6e-ae48-a8481046e0b7}.dtapart'
when closing it at Wed May 3 16:06:36 2017 -03 -0500 (2017-05-03 19:06:36 UTC).
Access to the file was allowed.
Of course the file was not corrupt and all that happened was that the file was still being downloaded when Sophos AV started to scan it and noticed that the file changed while doing so. Sophos sends so many e-mails reporting this non-sense false positive that I am going to uninstall it if I do not find a solution.
I only found the possibility to send all mails or none at all, and this is not acceptable because I must be informed of real viruses in the system.
Is there a way to set Sophos to not send those false positive mails?
Is there a way to report this to Sophos for them to fix the issue?
This thread was automatically locked due to age.