Hi everybody. I'm back using Splunk after some years, so I'm a bit "rusty". This is my scenario: suppose I have a network with some hosts, both workstation and servers. I know only that an antivirus is installed on them, but not which one for all of the hosts. What I know is: 1. Some hosts has Windows Defender, other not. 2. The Windows Defender Logs are configured to be sent to splunk. The other data mising is: the hosts with Defender, how are configured to get data? With a Splunk app? This is a data I have not. So, my question is: is there a Splunk query that I can use to discover if Defender is in execution or not. formatting the result to show the hostname of every machine?
... View more