Splunk Enterprise Security

Device discovery query

learnyboi1
Observer

Hello!

I was asked to find what IP addressable devices are listening on port 80 on our network. Can I find this information through a query? I'm new to Splunk analysis so I apologize if this seems basic.

Any and all help is greatly appreciated. Thanks!

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk only knows what it's told.  It doesn't know what devices are listening to what ports, but it might know (if told) that "at 10:00 today the 'netstat -l' command on host foo said these processes are listening on port 80" or "based on the network connection logs, here are the active connections to port 80".

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...