Endpoint events is the noisiest source Data Lineage draws on. Antivirus scanners, indexers, backup agents, VPN clients, and sync tools touch files constantly, and none of it is a user moving data. Endpoint Exceptions let you stop specific file paths and processes on managed devices from generating endpoint events for Data Lineage.
From any lineage graph, open Data Lineage Settings and select the Endpoint Exceptions tab. Changes take effect when you click Save. Endpoint Exceptions apply to the tenant.
File Path Exceptions
Use Endpoint Event File Path Exceptions to exclude a file or directory from generating endpoint events. Each row takes a File Path, an OS, and an optional Description. Click + to add a row and × to remove one.
- Paths support * as a wildcard for a path segment, so
C:\Users\*\juniper\juniper.exematches that file under every user profile. - Paths are matched per operating system.
Process Exceptions
Use Endpoint Event Process Exceptions to exclude every file operation performed by a given process. Each row takes a Process name, an OS, and an optional Description. winlogon.exe is the example the UI offers; the common cases are security agents, indexers, and backup clients.
Prefer a process exception over a path exception when the noise comes from a tool rather than a location. Excluding winlogon.exe is precise. Excluding C:\Users\*\Downloads to quiet one tool also hides every browser download on Windows, which is the single most common entry point for exfiltrated files.
What an Exception Does
An exception stops the Netskope Client from generating Data Lineage endpoint events for the matching path or process. The activity is not recorded and cannot be recovered later by removing the exception. Exceptions apply to new activity only. Endpoint activity already recorded stays in existing graphs.
Exceptions affect endpoint-sourced activity only. If the same file is also seen inline or through CASB API, that activity still appears.
Exceptions do not change Endpoint DLP policy evaluation. A process or path excepted here is still subject to Content Control and Device Control policies. To exclude a process from Endpoint DLP enforcement, go to Policies > Endpoint Protection > Content Control > Process Exception to manage a separate list.

