<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic No port_scan data in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91140#M6056</link>
    <description>&lt;P&gt;We're running Splunk for Asset Discovery 6.0 under Splunk 6 on an Ubuntu system.  The app has been running for a week, but we have no data in the asset_discovery index.  There are several input scripts defined and enabled, including '$SPLUNK_HOME/etc/apps/asset_discovery/bin/nmap.sh -A -O 192.168.100.0/24'.  If I run this command manually, I see data for all of the hosts in that subnet.  However, a search of 'index=asset_discovery' returns no events.  nmap is owned by root.  I assume it is running as root also since all of Splunk does so.&lt;/P&gt;

&lt;P&gt;I see nothing in splunkd.log other than "INFO  ExecProcessor - New scheduled exec process:&lt;BR /&gt;
/opt/splunk/etc/apps/asset_discovery/bin/nmap.sh -A -O 192.168.100.0/24."&lt;/P&gt;

&lt;P&gt;Where is my port_scan data going?&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 14:56:02 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-09-28T14:56:02Z</dc:date>
    <item>
      <title>No port_scan data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91140#M6056</link>
      <description>&lt;P&gt;We're running Splunk for Asset Discovery 6.0 under Splunk 6 on an Ubuntu system.  The app has been running for a week, but we have no data in the asset_discovery index.  There are several input scripts defined and enabled, including '$SPLUNK_HOME/etc/apps/asset_discovery/bin/nmap.sh -A -O 192.168.100.0/24'.  If I run this command manually, I see data for all of the hosts in that subnet.  However, a search of 'index=asset_discovery' returns no events.  nmap is owned by root.  I assume it is running as root also since all of Splunk does so.&lt;/P&gt;

&lt;P&gt;I see nothing in splunkd.log other than "INFO  ExecProcessor - New scheduled exec process:&lt;BR /&gt;
/opt/splunk/etc/apps/asset_discovery/bin/nmap.sh -A -O 192.168.100.0/24."&lt;/P&gt;

&lt;P&gt;Where is my port_scan data going?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:56:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91140#M6056</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-09-28T14:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: No port_scan data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91141#M6057</link>
      <description>&lt;P&gt;Did you check the default index?&lt;BR /&gt;
You can also check Manager&amp;gt;Index to see if the asset_discovery index was created and if it contains any data.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2013 17:42:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91141#M6057</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-10-09T17:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: No port_scan data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91142#M6058</link>
      <description>&lt;P&gt;I've searched 'sourcetype=port_scan' and 'source=nmap' without an index specified and get no results.&lt;/P&gt;

&lt;P&gt;Index manager says asset_discovery has zero events.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2013 17:45:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91142#M6058</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2013-10-09T17:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: No port_scan data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91143#M6059</link>
      <description>&lt;P&gt;What is the interval in the asset_discovery inputs.conf for that script?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2013 18:01:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91143#M6059</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-10-09T18:01:24Z</dc:date>
    </item>
    <item>
      <title>Re: No port_scan data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91144#M6060</link>
      <description>&lt;P&gt;1800 seconds&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2013 18:06:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91144#M6060</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2013-10-09T18:06:25Z</dc:date>
    </item>
    <item>
      <title>Re: No port_scan data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91145#M6061</link>
      <description>&lt;P&gt;Is the owner:group of the nmap binary root:root&lt;BR /&gt;&lt;BR /&gt;
And the permissions set to 4755?&lt;BR /&gt;
It could be a suid bit problem that you're not seeing when you run it yourself as root.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2013 18:23:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91145#M6061</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-10-09T18:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: No port_scan data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91146#M6062</link>
      <description>&lt;P&gt;-rwxr-xr-x 1 root root 1972032 Jan  4  2013 /usr/bin/nmap*&lt;/P&gt;

&lt;P&gt;Splunk is running as root so wouldn't nmap also run as root?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2013 18:26:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91146#M6062</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2013-10-09T18:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: No port_scan data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91147#M6063</link>
      <description>&lt;P&gt;I'm having the same problem. Running nmap through nmap.sh for a port scan works in the bash shell, even as the splunk user, but nothing is added for port_scan to Splunk. Tried running Splunk as root and splunk&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2013 12:06:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91147#M6063</guid>
      <dc:creator>mikaelbje</dc:creator>
      <dc:date>2013-10-11T12:06:15Z</dc:date>
    </item>
    <item>
      <title>Re: No port_scan data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91148#M6064</link>
      <description>&lt;P&gt;I figured it out. I had to chmod +s the nmap binary. I also had to chsnge ifconfig in nmap.sh to /sbin/ifconfig. This was in Ubuntu&lt;/P&gt;

&lt;P&gt;Restarting Splunk shouldn't be necessary AFAIK as you are only modifying Linux permissions for a binary that's called. However I have Splunk running as the "splunk" user, so if you're running as root it should absolutely work. My permissions for reference:&lt;/P&gt;

&lt;PRE&gt;
-rwsr-s--- 1 root adm 756464 Dec 14  2011 /usr/bin/nmap

groups splunk
splunk : splunk adm
&lt;/PRE&gt;

&lt;P&gt;Running this from command line works fine, also as a scripted input in Splunk:&lt;/P&gt;

&lt;PRE&gt;
/opt/splunk/etc/apps/asset_discovery/bin/nmap.sh -A -O -t 172.24.201.0/24
&lt;/PRE&gt;

&lt;P&gt;Since this is Ubuntu &lt;EM&gt;sh&lt;/EM&gt; is a symbolic link to &lt;EM&gt;dash&lt;/EM&gt;, not &lt;EM&gt;bash&lt;/EM&gt;, but it should work in bash too.&lt;/P&gt;

&lt;P&gt;asset_discovery/local/inputs.conf&lt;BR /&gt;
&lt;PRE&gt;&lt;BR /&gt;
[script://./bin/nmap.sh -A -O -t 172.24.201.0/24]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
index = asset_discovery&lt;BR /&gt;
interval = 3600&lt;BR /&gt;
sourcetype = port_scan&lt;BR /&gt;
source = nmap&lt;BR /&gt;
&lt;/PRE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:57:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91148#M6064</guid>
      <dc:creator>mikaelbje</dc:creator>
      <dc:date>2020-09-28T14:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: No port_scan data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91149#M6065</link>
      <description>&lt;P&gt;I made the same changes and still no data.  Did you have to restart Splunk?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2013 12:05:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91149#M6065</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2013-10-15T12:05:11Z</dc:date>
    </item>
    <item>
      <title>Re: No port_scan data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91150#M6066</link>
      <description>&lt;P&gt;I updated my answer. Not sure if it's any help. You might try restarting Splunk just in case.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2013 06:47:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91150#M6066</guid>
      <dc:creator>mikaelbje</dc:creator>
      <dc:date>2013-10-16T06:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: No port_scan data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91151#M6067</link>
      <description>&lt;P&gt;I restarted Splunk and still am getting no port_scan data. In fact, my asset_discovery index contains nothing at all.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:59:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91151#M6067</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-09-28T14:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: No port_scan data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91152#M6068</link>
      <description>&lt;P&gt;Can you paste your inputs.conf?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2013 12:24:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91152#M6068</guid>
      <dc:creator>mikaelbje</dc:creator>
      <dc:date>2013-10-16T12:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: No port_scan data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91153#M6069</link>
      <description>&lt;P&gt;[script://./bin/nmap.sh]&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;[script://./bin/nmap.sh -A -O]&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;[script:///opt/splunk/etc/apps/asset_discovery/bin/nmap.sh -p14147 -t 172.16.42.&lt;BR /&gt;
64 172.16.42.220 172.16.42.230]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
index = asset_discovery&lt;BR /&gt;
interval = 60&lt;BR /&gt;
source = nmap&lt;BR /&gt;
sourcetype = port_scan&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:59:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91153#M6069</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-09-28T14:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: No port_scan data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91154#M6070</link>
      <description>&lt;P&gt;Rich, I'm not sure what's up here.  Could you shoot me an email when you have a chance and we can try doing some debugging?  I'm curious about what's happening here as well, particularly since I really haven't changed the scanning stuff in the latest version.  mwilson at splunk dot com.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2013 20:47:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91154#M6070</guid>
      <dc:creator>mw</dc:creator>
      <dc:date>2013-10-16T20:47:35Z</dc:date>
    </item>
    <item>
      <title>Re: No port_scan data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91155#M6071</link>
      <description>&lt;P&gt;Redirecting the nmap.sh output to a file showed nmap was failing because of a missing OpenSSL library.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;nmap: /opt/splunk/lib/libcrypto.so.1.0.0: version `OPENSSL_1.0.0' not found (required by nmap)
nmap: /opt/splunk/lib/libssl.so.1.0.0: version `OPENSSL_1.0.0' not found (required by nmap)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Adding &lt;CODE&gt;unset LD_LIBRARY_PATH&lt;/CODE&gt; to nmap.sh fixed the problem.&lt;/P&gt;

&lt;P&gt;Thanks to Splunk tech support for their help with this.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2013 12:51:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91155#M6071</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2013-10-18T12:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: No port_scan data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91156#M6072</link>
      <description>&lt;P&gt;The reason setting the executable setUID works (which I don't recommend!) is that Linux sanitizes the environment when jumping through a setuid gate, specifically dropping LD_LIBRARY_PATH and other linker controls, so that a user cannot execute arbitrary code as root trivially.&lt;/P&gt;

&lt;P&gt;Thus this indirectly requests the action the app should have taken in the first place, to strip the library path when running a system binary.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:11:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91156#M6072</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2020-09-28T15:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: No port_scan data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91157#M6073</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I also have a similar problem.  I can see data within a splunk search "index=asset_discovery sourcetype=port_scan", but the eventtype port_scan (index=asset_discovery sourcetype=port_scan "Host:" "Ports:" "Ignored State:" ) doesn't produce anything as my script isn't generating any "Ignored State:"&lt;BR /&gt;&lt;BR /&gt;
I am running the following script:&lt;BR /&gt;
/opt/splunk/etc/apps/asset_discovery/bin/nmap.sh -A -O -t 172.20.32.0/24 --max-retries 1 --osscan-guess --system-dns&lt;BR /&gt;
and I have added "unset LD_LIBRARY_PATH" to the nmap.sh script as well as ensuring that nmap is chmod'ed so the splunk user can use it.&lt;BR /&gt;
Have a missed something and argument when calling the script?&lt;BR /&gt;
Mario&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:58:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91157#M6073</guid>
      <dc:creator>mario_traf</dc:creator>
      <dc:date>2020-09-28T15:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: No port_scan data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91158#M6074</link>
      <description>&lt;P&gt;You can edit the eventtype to remove that portion.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2014 05:14:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91158#M6074</guid>
      <dc:creator>mw</dc:creator>
      <dc:date>2014-02-26T05:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: No port_scan data</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91159#M6075</link>
      <description>&lt;P&gt;I wasn't sure if the ignored state was needed or not.&lt;BR /&gt;
anyway, I have done as suggested.&lt;BR /&gt;
turns out that the version of nmap I am using doesn't generate the "Ignored State:" text anymore&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2014 07:59:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/No-port-scan-data/m-p/91159#M6075</guid>
      <dc:creator>mario_traf</dc:creator>
      <dc:date>2014-02-27T07:59:10Z</dc:date>
    </item>
  </channel>
</rss>

