Thanks much! Going to try and use this to find hosts that are not reporting sysmon data. | tstats count WHERE index=* by host sourcetype | eval count=if(sourcetype="WinEventLog:Microsoft-Windows-Sysmon/Operational",1,0) | stats sum(count) as count by host #| search NOT (<exclude/filter out systems as needed here>, example: index=syslog) | where count = 0 | table host | rename host as "Hosts Not Sending Sysmon"
... View more