Monitoring Splunk

Monitor That Windows 7 is listening on a specified port

scamarda
New Member

I need to monitor that an application is active on a Windows 7 machine. The application listens on port 80. If the application is up, the Windows machine will show it is listening on port 80. A netstat -ano would be good to show that the application is active. I am using the universal forwarder. Can you give me an idea of what I can use to verify the application is active and listening on port 80?

Tags (1)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You could deploy a script to your UF that periodically runs things like the netstat command you mentioned. Splunk will index the output and you can search/alert/report from there. I'm sure you can also get a list of running processes/services as well.

To make sure you don't reinvent the wheel you should check if https://splunkbase.splunk.com/app/1680/ has a similar thing already built.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...