Dashboards & Visualizations

source type: Script:ListeningPorts

cplau
Loves-to-Learn

Hi all,

I have just installed an app called "CIS Top 20 Critical Controls". In one of the dashboards, I found that it looks for events from sourcetype=Script:ListeningPorts.

I would to know how to collect this type of events. It seems that I don't have this sorucetype in my testing system.

Please advise. Thanks a lot.

Rgds.,
Pong

Tags (1)
0 Karma

jwalker_splunk
Splunk Employee
Splunk Employee

Hi Pong,
The events for this sourcetype come from the win_listening_ports.bat script that is included in the Windows TA. The script is disabled in the TA's default inputs.conf. It can be enabled by creating an inputs.conf file in the local directory of the TA with:

[script://.\bin\win_listening_ports.bat]
disabled=0

Cheers,
Jon

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...