Jump to content

Recommended Posts

Posted

Hello,

 

We are using endpoint security product 11.1 for our end users on windows 10/11 pc's and managing it via Eset Protect on-prem server console.

Recently a users pc was compromised, and we suspect that the user didn't had eset security product installed, however, user claims that the eset product was already installed and the user just uninstalled it and reinstalled it again.

 

But when we saw the Event viewer: app/system logs we could see details of installation only and no events of uninstallation.

We checked the audit logs from the server and could see only the installation details:

12/07/2024 09:11 Computer Create

Creating computer '(desktop name)' in group 'All\(device folder location)'.

 

Is there any way to find out that a uninstall happened for the eset endpoint security product and the eset mgmt agemt?

 

Thanks

  • Solution
Posted

Thanks Marcos, We found what we needed, this can be closed.

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...