Hello,
I am looking to create a custom analytic that will alert when a software installation occurs. I found this: custom_analytic_detections/app_bundle_installed
It does work and creates alerts, however it alerts on everything installed and there are multiple alerts for each item.
Is there a way to filter out System or Root level installs? That way Jamf patches/pushes don't trigger alerts?
Thanks,
Don