Alerting

How to use splunk for data monitoring and alert

Sunjux
Explorer

Dear Splunkers:

I use nmap to monitor my device and contain these logs to Splunk,(every 6hrs)

These data only include ip and tcp open port,

E.g:

      ip_addr 1.2.3.4
      port_list 80\n433\n3389

Now I want to notify me when there is a new tcp port open(Compare the results of the previous two scans,which is the data twelve hours ago )

Which spl syntax should I use? Can someone give me any direction? thank you very much 🙂

 

 

Labels (1)
0 Karma
1 Solution

Sunjux
Explorer

Dear all:

I found the solution in this post

Recommend to people who have the same questions as me!😁

 

View solution in original post

0 Karma

Sunjux
Explorer

Dear all:

I found the solution in this post

Recommend to people who have the same questions as me!😁

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you share some anonymised event as you have them in splunk?

0 Karma

Sunjux
Explorer

@ITWhisperer 

Hi ,of course!Please refer to the following picture,

I have captured two fields, namely 「ip_add」 and「 port_list」

thanks!

 

Sunjux_0-1623825553715.pngSunjux_1-1623825585228.pngSunjux_2-1623825609650.png

 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...