Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to raise the alert for sourcetype=netstat

$
0
0
Hi Splunker, How can i Write the splunk query to show the state of a port for local address? The result of netstat is for the whole ports on the particular server, and the results be like: Proto Recv-Q Send-Q LocalAddress ForeignAddress State tcp 0 0 0.0.0.0:111 0.0.0.0:* LISTEN Now in this case, how shall i write the query if the State for port 111 changes from Listen to CLOSED_WAIT or Closed etc...?

Viewing all articles
Browse latest Browse all 47296


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>