Hi all,
I have just installed an app called "CIS Top 20 Critical Controls". In one of the dashboards, I found that it looks for events from sourcetype=Script:ListeningPorts.
I would to know how to collect this type of events. It seems that I don't have this sorucetype in my testing system.
Please advise. Thanks a lot.
Rgds.,
Pong
Hi Pong,
The events for this sourcetype come from the win_listening_ports.bat script that is included in the Windows TA. The script is disabled in the TA's default inputs.conf. It can be enabled by creating an inputs.conf file in the local directory of the TA with:
[script://.\bin\win_listening_ports.bat]
disabled=0
Cheers,
Jon