Alerting

How to use splunk for data monitoring and alert

Sunjux
Explorer

Dear Splunkers:

I use nmap to monitor my device and contain these logs to Splunk,(every 6hrs)

These data only include ip and tcp open port,

E.g:

      ip_addr 1.2.3.4
      port_list 80\n433\n3389

Now I want to notify me when there is a new tcp port open(Compare the results of the previous two scans,which is the data twelve hours ago )

Which spl syntax should I use? Can someone give me any direction? thank you very much 🙂

 

 

Labels (1)
0 Karma
1 Solution

Sunjux
Explorer

Dear all:

I found the solution in this post

Recommend to people who have the same questions as me!😁

 

View solution in original post

0 Karma

Sunjux
Explorer

Dear all:

I found the solution in this post

Recommend to people who have the same questions as me!😁

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you share some anonymised event as you have them in splunk?

0 Karma

Sunjux
Explorer

@ITWhisperer 

Hi ,of course!Please refer to the following picture,

I have captured two fields, namely 「ip_add」 and「 port_list」

thanks!

 

Sunjux_0-1623825553715.pngSunjux_1-1623825585228.pngSunjux_2-1623825609650.png

 

0 Karma
Get Updates on the Splunk Community!

Exciting News: The AppDynamics Community Joins Splunk!

Hello Splunkers,   I’d like to introduce myself—I’m Ryan, the former AppDynamics Community Manager, and I’m ...

The All New Performance Insights for Splunk

Splunk gives you amazing tools to analyze system data and make business-critical decisions, react to issues, ...

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...