I hadn't made any changes, and put off modifying the csf.pignore file for a couple of months.
Today I checked the csf.pignore file, and there is already an entry for
Looking at the alerts it looks like I need to add wildcarded virtfs entries to stop the alertsexe:/usr/libexec/openssh/sftp-server
Is this right? LFD has echoed the command line identical to an entry in the ignore file, Shouldn't my sftp server already be excluded?Executable: /home/virtfs/tw/usr/libexec/openssh/sftp-server
Command Line: /usr/libexec/openssh/sftp-server