You can create a new query or duplicate the original one for failed deployments and filter it for most recent time frames, such as within last day. It would be a threat event query for event id 2412. The query would need to be table type. Then set up a server task to run that query and secondary action to tag the systems with a tag you have created for this that you can run daily. Once your systems have the products installed, you can set up query to run to detect that, then action in server task to remove tag.
The only thing about that is that there is no way to add a condition where event occurred more than once.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?