Dashboards & Visualizations

source type: Script:ListeningPorts

cplau
Loves-to-Learn

Hi all,

I have just installed an app called "CIS Top 20 Critical Controls". In one of the dashboards, I found that it looks for events from sourcetype=Script:ListeningPorts.

I would to know how to collect this type of events. It seems that I don't have this sorucetype in my testing system.

Please advise. Thanks a lot.

Rgds.,
Pong

Tags (1)
0 Karma

jwalker_splunk
Splunk Employee
Splunk Employee

Hi Pong,
The events for this sourcetype come from the win_listening_ports.bat script that is included in the Windows TA. The script is disabled in the TA's default inputs.conf. It can be enabled by creating an inputs.conf file in the local directory of the TA with:

[script://.\bin\win_listening_ports.bat]
disabled=0

Cheers,
Jon

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...