How to Check Anti-Virus (AV) Status in Windows Systems Using Saner

Modified on Wed, 24 Sep at 5:21 PM

Overview
This article guides you through checking the Anti-Virus (AV) status on Windows systems using Saner’s Endpoint Management module, scheduling queries, and taking appropriate actions based on results.


Prerequisites

Before beginning, ensure the following:

  • You have access to the Saner console with permissions to use Endpoint Management.

  • Agents are installed and running on the target Windows systems.


Steps to Check Anti-Virus Status

Step 1: Log in and Select Account

  • Log in to Saner.

  • Choose the Organization and corresponding Account where you want to check AV status.


Step 2: Access Endpoint Management

  • Select the Endpoint Management module.


Step 3: Open Checks

  • Click on Checks in the top-right corner.


Step 4: Select Windows Security Checks

  • From the drop-down menu, select Windows → System Security.


Step 5: Select Anti-Virus Information

  • Scroll down to see the highlighted checks in green.

  • Select Anti-Virus Information.


Step 6: Schedule Query Execution

  • Click Trigger to schedule query execution for the agent.

  • Fill in the Query Trigger Settings:

    • Query run count time in seconds.

    • Query frequency in minutes.

    • Query Trigger Time Frame in the Schedule options pane.

  • Click Update.


Step 7: Select Scope

  • Click Scope to choose the target scope for the query.


Step 8: Submit Query

  • Click Submit to send the query to the agent.


Step 9: View Results

  • In the Result Pane, check details such as:

    • antivirus_name

    • instance_guid

    • path_to_signed_product_exe

    • path_to_signed_reporting_exe

    • product_enabled

    • product_uptodate

    • product_state

    • Hosts

  • Results can be downloaded in CSV format.


Step 10: Take Actions Based on Results

  • Possible actions include Service start, Start process, and Application management.

  • Click the desired action to be redirected to the Create Response page.

  • All responses created for the selected check can be viewed in Created Actions.


Note:
Following these steps allows administrators to monitor AV status across Windows systems, respond to issues proactively, and maintain endpoint security compliance.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article