TQSH 0 Posted July 17 Posted July 17 Hello, We are using endpoint security product 11.1 for our end users on windows 10/11 pc's and managing it via Eset Protect on-prem server console. Recently a users pc was compromised, and we suspect that the user didn't had eset security product installed, however, user claims that the eset product was already installed and the user just uninstalled it and reinstalled it again. But when we saw the Event viewer: app/system logs we could see details of installation only and no events of uninstallation. We checked the audit logs from the server and could see only the installation details: 12/07/2024 09:11 Computer Create Creating computer '(desktop name)' in group 'All\(device folder location)'. Is there any way to find out that a uninstall happened for the eset endpoint security product and the eset mgmt agemt? Thanks
Administrators Marcos 5,469 Posted July 17 Administrators Posted July 17 Please provide logs collected with ESET Log Collector from the machine in question.
Solution TQSH 0 Posted July 18 Author Solution Posted July 18 Thanks Marcos, We found what we needed, this can be closed.
Recommended Posts