    Report on execution of targeted processes


      Ladies, Gents,


      I'm trying to setup, via policy, a means to report on specified processes/filenames when executed.   The only way I think I can accomplish this is via access protection > file/folder protection and set to just warn, not block.  The problem is the list of executable names is over 30 and it seems I cannot specificy multiple names per access protection rule (i tried "separating names by , ; and space with no luck) which makes using this method kind of pain if I have to plug in 30+ different rules, one per process.


      Anyone doing anything like this currently or know of a better way to get it done?