Hi,
how to build a search to check endpoint agent is installed on windows/linux host by running a query.
Scenario : i have a all the assets in a lookup.csv and now i want to run the search query comparing the on-baorded logs(symantec.exe) with lookup file which is have assets name, whether Symantec agent is installed or not on the host.
Thanks in advance
If you need help in building the Splunk query, please provide the format of the lookup data and describe what you need as output more clearly.
This blog entry has a good write-up on that.
https://www.duanewaddle.com/proving-a-negative/