Hello,
So I have a query were I want to filter out duplicate entries directly in ePO. I'm looking for if a device has done a certain thing, not if it the device has done it multiple times.
So the query is basically.
Has any device this type of event in the Threat Events = if so then the hostname should only appear once in my query.
Is this possible to do directly in ePO?
BR
Mick
Bumping to see if anyone has an answer 🙂 Updating my question so it makes more sense.
1. I want to make a report from the query and I'm only interested in seeing if the system has done it or not. If the system has then I want to see it listed just once in the query.
This is so that the report is easier to read and looks better when showing it to my colleagues.
2. I want to use the tag functionality to tag these systems that are found via the query.
BR
Mick
You would get more than one entry for a system if there is more than one event. You can try creating it as a chart where system names are one of the labels, or you can group by system name. Otherwise there is no logic to filter it to return only one system name as a table. Tagging option would still work if more than one entry exists for a given system name. You just have to have the query as a table and not a chart, if that is an action you want to take on the query.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA