Hi @everyone, @skoelpin,
Can you please help me in this.
I have firefox program installed in my system . Now , I am getting in my splunk event when I ran the query for what are the software I have installed in my system and this is expected.
Now, If I remove/uninstall firefox from my system and then search the splunk query , it still appears in the splunk event. There is a field in the event called LastUsedTime and the reason we are still seeing the events as the logs retention period is for 90 days.
Now, I want a fresh result of the search where application name ( firefox) shall not come if I uninstall the firefox from the system.
Can help me to add a filter in the search listing for events having LastUsedTime newer than a period of choice( 1 week, 1 month, etc) or any other workaround for this ?
Thanks again for your help.
Binay Agarwal
... View more