- Disabled by default: outgoing
- Active by default: incoming, coming from internal and external servers, and reported by users
local.properties file located at activeguard/core/rule_sets/90_local/params/:
Tika active in listening modesTika is still used by default for URL extraction when Sandbox is switched off. Therefore, the above rule to prevent traffic from being sent to Tika is essential if you don’t want to use Tika.
Disabling Tika
Tika should not be disabled in any production environment as it will severly impact classification accuracy. However, if needed, it can be disabled using the Expert Editor. In theactiveguard/core/active_guard.yml file, add the following lines:
Processed file formats
Tika extracts text and URLs from a defined set of file formats.The full list of processed file formats is documented in
Detection Defaults → Tika processed file formats.
Password required.