Microsoft AntiMalware Scan Completion WinEventLog:System SplunkNinja Vote Up +0 Vote Down -0You already voted! This query lists a count by scan type, duration of scan, and the host the scan took place on. Modify as needed. sourcetype="WinEventLog:System" SourceName="Microsoft Antimalware" EventCode=1001 | stats count by Scan_Type, Scan_Time, host Share This: Tagged: A/Vanti-malwareAnti-virusWinEventLog:System