> Source: [sk129753](https://support.checkpoint.com/results/sk/sk129753)

# sk129753 - How to disable SandBlast Agent Data Collection

| Property | Value |
|----------|-------|
| Solution ID | sk129753 |
| Date Created | 2018-06-18 |
| Last Modified | 2022-08-01 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X, R82.20, R82.10, R82, R81.20 |
| OS | Windows |

## Solution

SandBlast Agent Data Collection sends anonymized incident related data to the Check Point ThreatCloud. This data helps improve protections for all our customers. The data currently being sent may include:  
* Anonymized Forensic Reports
* Memory Dumps of Malicious/Compromised Processes (currently disabled)
* Malicious Files (currently disabled)  

To disable Data Collection, do this:

1. Open SmartEndpoint console.  

2. Go to the *Policy* tab.  

3. Open the *SandBlast Agent Forensics, Remediation And Anti-Ransomware* policy.  

4. Edit the *Monitoring and Exclusions* action.  

5. Click on *Add location* .  

6. Choose *Process* .  

7. Add this text to the *Process name* test box:  

   `<DcPolicy enabled="false" xmlns="http://schema.checkpoint.com/policy/v1/"></DcPolicy>`   

8. Click "OK".  

9. *Save* and *Install Policy* .  

   [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk129753/Policy1806180225.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk129753/Policy1806180225.png "Click the image to see it in full size in a new tab/window")

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
