I’m trying to find out what SEP version 14 (Symantec Endpoint Protection) definition (def) is currently on a Mac client.
I know the folder path is:
"/Library/Application Support/Symantec/Silo/NFM/Definitions/virusdefs/"
and that the file that I’d be looking for starts with “20” (for now it would be “2018…”, later “2019”, etc.)
I set up analysis to retrieve a property for this, using the following relevance:
name of files whose (name of it as lowercase starts with "20") of folder "/Library/Application Support/Symantec/Silo/NFM/Definitions/virusdefs/"
Unfortunately I’m not getting back any results for that part of my analysis. Suggestions on what is wrong here?