Monitoring Splunk

Monitor That Windows 7 is listening on a specified port

scamarda
New Member

I need to monitor that an application is active on a Windows 7 machine. The application listens on port 80. If the application is up, the Windows machine will show it is listening on port 80. A netstat -ano would be good to show that the application is active. I am using the universal forwarder. Can you give me an idea of what I can use to verify the application is active and listening on port 80?

Tags (1)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You could deploy a script to your UF that periodically runs things like the netstat command you mentioned. Splunk will index the output and you can search/alert/report from there. I'm sure you can also get a list of running processes/services as well.

To make sure you don't reinvent the wheel you should check if https://splunkbase.splunk.com/app/1680/ has a similar thing already built.

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...