here is an example you can modify. This is for showing how long per MB a
scan is taking


 SELECT Distinct

VRS.Netbios_Name0 as 'Computer Name',

(SUM(LD.Size0) - SUM(ld.FreeSpace0)) / DATEDIFF(HOUR,HS.
LastFullScanDateTimeStart,HS.LastFullScanDateTimeEnd) AS [Full Scan MB
Scanned Per Hour],

(SUM(LD.Size0) - SUM(ld.FreeSpace0)) / DATEDIFF(HOUR,HS.
LastQuickScanDateTimeStart,HS.LastQuickScanDateTimeEnd) AS [Quick Scan MB
Scanned Per Hour],

(SUM(LD.Size0) - SUM(ld.FreeSpace0)) / 1024 AS [GBDataSize],

DATEDIFF(HOUR,HS.LastQuickScanDateTimeStart,HS.LastQuickScanDateTimeEnd) AS
[LastQuickScanDurationInHours],

DATEDIFF(HOUR,HS.LastFullScanDateTimeStart,HS.LastFullScanDateTimeEnd) AS
[LastFullScanDurationInHours],

OS.TotalVisibleMemorySize0 AS [TotalVisibleMemory],

P.Name0 AS [CPU],

SUBSTRING( convert(varchar, DATEADD(ss,SUM(datediff(ss,HS.
LastQuickScanDateTimeStart, HS.LastQuickScanDateTimeEnd)),CAST('00:00:00' AS
TIME)),108),1,5) AS [LastQuickScanDuration],

SUBSTRING( convert(varchar, DATEADD(ss,SUM(datediff(ss,HS.
LastFullScanDateTimeStart, HS.LastFullScanDateTimeEnd)),CAST('00:00:00' AS
TIME)),108),1,5) AS [LastFullScanDuration],

 HS.LastQuickScanDateTimeStart,

HS.LastQuickScanDateTimeEnd,

 HS.LastFullScanDateTimeStart,

HS.LastFullScanDateTimeEnd,

 HS.LastQuickScanAge as 'Days since last quick scan',

HS.LastFullScanAge as 'Days since last full scan',

OS.Caption0 as 'Operating System'

  FROM v_R_System VRS

Left Join v_GS_LOGICAL_DISK LD on LD.ResourceID = VRS.ResourceID

INNER JOIN v_GS_AntimalwareHealthStatus HS ON HS.ResourceID = VRS.ResourceID


INNER JOIN v_GS_OPERATING_SYSTEM OS ON VRS.ResourceID = OS.ResourceID

Left Join v_GS_PROCESSOR P on P.ResourceID = VRS.ResourceID

 Where LD.Name0 NOT IN('Q:','A:')

AND (DATEDIFF(HOUR,HS.LastQuickScanDateTimeStart,HS.LastQuickScanDateTimeEnd
) IS Not Null OR DATEDIFF(HOUR,HS.LastFullScanDateTimeStart,HS.
LastFullScanDateTimeEnd) Is Not Null)

ANd LD.Size0 Is Not Null

AND DATEDIFF(HOUR,HS.LastFullScanDateTimeStart,HS.LastFullScanDateTimeEnd) >
0

AND DATEDIFF(HOUR,HS.LastQuickScanDateTimeStart,HS.LastQuickScanDateTimeEnd)
> 0

Group By

VRS.Netbios_Name0,

OS.TotalVisibleMemorySize0,

P.Name0,

  OS.Caption0,

HS.LastQuickScanDateTimeStart,

HS.LastQuickScanDateTimeEnd,

HS.LastFullScanDateTimeStart,

HS.LastFullScanDateTimeEnd,

HS.LastQuickScanAge,

HS.LastFullScanAge

  Order By [LastQuickScanDurationInHours] Desc

On Thu, Nov 20, 2014 at 6:31 PM, Todd Hemsell <[email protected]> wrote:

> they are all in here.
>
> v_GS_AntimalwareHealthStatus
>
>
>
>
>
>
>
>
> On Mon, Nov 17, 2014 at 3:51 PM, Lutz, Ken <[email protected]>
> wrote:
>
>>  I just run this PowerShell script:  (note:  the get-eventlog line is
>> all one line.)
>>
>>
>>
>> param
>>
>>   (
>>
>>   [Parameter(Mandatory=$True)]
>>
>>   [string]$Computername
>>
>>  )
>>
>>
>>
>> $PastDate = [DateTime]::Now.AddDays(-30)
>>
>>
>>
>> get-eventlog -ComputerName $Computername -LogName system -after $PastDate
>> | Where-Object {(($_.eventid -like "1001") -or  ($_.eventid -like "1000")
>> -or  ($_.eventid -like "1002") ) -and ($_.source -like "*antimal*")} |
>> Select-Object TimeGenerated, EntryType, Source, EventID, UserName, Message
>> | out-gridview
>>
>>
>>
>> *Thanks,*
>>
>> *Ken …*
>>
>>
>>
>> *From:* [email protected] [mailto:
>> [email protected]] *On Behalf Of *Marcum, John
>> *Sent:* Monday, November 17, 2014 11:38 AM
>> *To:* SMS List ([email protected])
>> *Subject:* [mssms] List of All SCEP Scans for a Given Machine
>>
>>
>>
>> Does anyone have a report (or know where in the database I can find) a
>> list of all scans within the past xx days and the results of the scan for a
>> given computer?
>>
>>
>>
>>
>>
>>
>>
>>
>>  * ------------------------------ *
>>
>> *        John Marcum*
>>
>>             MCITP, MCTS, MCSA
>> *              Desktop Architect*
>>
>> *   Bradley Arant Boult Cummings LLP*
>>    * ------------------------------ *
>>
>>
>>
>>   [image: H_Logo]
>>
>>
>>
>>
>>  ------------------------------
>>
>>
>> Confidentiality Notice: This e-mail is from a law firm and may be
>> protected by the attorney-client or work product privileges. If you have
>> received this message in error, please notify the sender by replying to
>> this e-mail and then delete it from your computer.
>>
>>
>>
>>
>
>



Reply via email to