Hi
I'm working on writing a discovery query for a pack. My use case is to disable event based queries (in a pack) if 'auditd' is running on the system. So, discovery query should return 0 rows if any process name matching '%auditd%' is present else return 1 or more rows. Any pointers on how to achieve this ?
Thanks