Dashboards & Visualizations

source type: Script:ListeningPorts

cplau
Loves-to-Learn

Hi all,

I have just installed an app called "CIS Top 20 Critical Controls". In one of the dashboards, I found that it looks for events from sourcetype=Script:ListeningPorts.

I would to know how to collect this type of events. It seems that I don't have this sorucetype in my testing system.

Please advise. Thanks a lot.

Rgds.,
Pong

Tags (1)
0 Karma

jwalker_splunk
Splunk Employee
Splunk Employee

Hi Pong,
The events for this sourcetype come from the win_listening_ports.bat script that is included in the Windows TA. The script is disabled in the TA's default inputs.conf. It can be enabled by creating an inputs.conf file in the local directory of the TA with:

[script://.\bin\win_listening_ports.bat]
disabled=0

Cheers,
Jon

Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...