Hello!
I was asked to find what IP addressable devices are listening on port 80 on our network. Can I find this information through a query? I'm new to Splunk analysis so I apologize if this seems basic.
Any and all help is greatly appreciated. Thanks!
Splunk only knows what it's told. It doesn't know what devices are listening to what ports, but it might know (if told) that "at 10:00 today the 'netstat -l' command on host foo said these processes are listening on port 80" or "based on the network connection logs, here are the active connections to port 80".