> Source: [sk116857](https://support.checkpoint.com/results/sk/sk116857)

# sk116857 - Files are randomly not getting scanned and emulated by Threat Emulation

| Property | Value |
|----------|-------|
| Solution ID | sk116857 |
| Date Created | 2017-04-20 |
| Last Modified | 2017-05-02 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Files are randomly not getting scanned and emulated by Threat Emulation.
* Manual test emulation via `te_add_file` works as expected.
* `dlpu.elg` shows:

  ```
  dlpu_mngr_av_add_file_buffer: should bypass TE emulation (inactive mode) 
  ```

## Cause

An exception configured with action 'Inactive' on the Threat Emulation rulebase is preventing files from being scanned.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1492057430640/ThreatEmulation_exclusion1704122239.PNG)

## Solution

The rulebase should have an exception more specific than the actual Threat Emulation rule, otherwise it will create a conflict and files will not be scanned. Remove or modify the exclusion with a more specific rule.

**Example:**

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1492057430640/ThreatEmulation_no_exclusion1704122241.PNG)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
