Hi @ASierra, what the frequency of this alert? if it's e.g. every day, you could run a search like this: index=your_index "Windows Installer installed the product" earliest=-24h
| rex "Product Name: (?<Product_Name>.+)\. Product Version: (?<Product_Version>.+)\. Product Language"
| stats dc(Product_Version) AS dc_pv BY host Product_Name
| where dc_pv>1 Ciao. Giuseppe ,
... View more