Hi,
Thank you for posting in Symantec community.
I would be glad to answer your query.
How to Verify if an Endpoint Client has Automatically Excluded an Application or Directory.
http://www.symantec.com/docs/TECH105814
To know more about logs, you should refer this article.
Creating exceptions from log events in Symantec Endpoint Protection Manager
http://www.symantec.com/docs/HOWTO54867
It's a managed client? then can try the following steps.
Creating Centralized Exception Policies in Symantec Endpoint Protection Manager.
http://www.symantec.com/docs/TECH104326
How to Create Exceptions or Exclusions for Tamper Protection Alerts that have already been logged.
http://www.symantec.com/business/support/index?page=content&id=TECH92553&locale=en_US