Dashboards & Visualizations

source type: Script:ListeningPorts

cplau
Loves-to-Learn

Hi all,

I have just installed an app called "CIS Top 20 Critical Controls". In one of the dashboards, I found that it looks for events from sourcetype=Script:ListeningPorts.

I would to know how to collect this type of events. It seems that I don't have this sorucetype in my testing system.

Please advise. Thanks a lot.

Rgds.,
Pong

Tags (1)
0 Karma

jwalker_splunk
Splunk Employee
Splunk Employee

Hi Pong,
The events for this sourcetype come from the win_listening_ports.bat script that is included in the Windows TA. The script is disabled in the TA's default inputs.conf. It can be enabled by creating an inputs.conf file in the local directory of the TA with:

[script://.\bin\win_listening_ports.bat]
disabled=0

Cheers,
Jon

0 Karma
Get Updates on the Splunk Community!

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...