Dear Splunkers:
I use nmap to monitor my device and contain these logs to Splunk,(every 6hrs)
These data only include ip and tcp open port,
E.g:
ip_addr 1.2.3.4
port_list 80\n433\n3389
Now I want to notify me when there is a new tcp port open(Compare the results of the previous two scans,which is the data twelve hours ago )
Which spl syntax should I use? Can someone give me any direction? thank you very much 🙂
Can you share some anonymised event as you have them in splunk?
Hi ,of course!Please refer to the following picture,
I have captured two fields, namely 「ip_add」 and「 port_list」
thanks!