Forum Discussion
Custom Detection rule to find Inactive Device
Princely Much appreciated your response to my query. Unfortunately, It does not return any result even if I choose the last 30 days. Please let me know if you happen to know how to set the Time range in the query.
However, I do get all inactive devices by running the below query
Arjun_Rajan
The query you had mentioned seems to be giving the health status of each device.
And the one I had mentioned would specifically return the devices with a sensor enabled but no sensor data returned. Do you not have any hosts in your environment that match this criteria ? I suspect that is the case here.
Regards,
Princely Dmello
- Akash553Nov 25, 2022Copper Contributor
hello Brother
i need to know in this condition for detection, how should we test it like should i have to disable the network connection of the machine and then wait for some time? If yes then how much time it requires
Please mention the test how should i test in testing environment?