{"id":1158,"date":"2015-03-07T09:10:40","date_gmt":"2015-03-07T15:10:40","guid":{"rendered":"http:\/\/www.nathanhunstad.com\/blog\/?p=1158"},"modified":"2015-03-07T09:13:49","modified_gmt":"2015-03-07T15:13:49","slug":"splunk-reporting-port-scans","status":"publish","type":"post","link":"https:\/\/www.nathanhunstad.com\/blog\/2015\/03\/splunk-reporting-port-scans\/","title":{"rendered":"Splunk Reporting: Port Scans"},"content":{"rendered":"<p>It\u2019s been a while since I\u2019ve done some Splunk work on my home network, but lately I&#8217;ve been\u00a0thinking about port scans, specifically about reporting on port scans against my environment.\u00a0I\u2019m not terribly worried about people scanning my network since it is quite locked down, but why not check on it to see if anything interesting is going on? Before too long I had a new dashboard; details below the jump.<\/p>\n<p><!--more--><\/p>\n<p>The last time <a href=\"http:\/\/www.nathanhunstad.com\/blog\/2014\/08\/splunk-reporting-mapping-brute-force-attempts\/\" target=\"_blank\">I did this<\/a>, I was trying to map brute force attempts. Port scans are similar, so I started with the search I did for the brute force attempts, tweaked it a bit with some help from the internets, and this is what I got:<\/p>\n<p><span style=\"font-family: 'Courier New';\">index=firewall RuleName=WAN-*default-D | bucket _time span=30 | eventstats dc(DPT) AS PortsScanned by SRC, _time | where PortsScanned &gt; 5 | dedup SRC, PortsScanned | table SRC, PortsScanned, _time<\/span><\/p>\n<p>Walking through this step by step: the first section says to search my firewall index, and to only include logs of rules that match WAN-*default-D, which is my rule nomenclature for traffic that originates from the WAN zone and is dropped by my default drop rule (meaning no pre-existing connection existed, it just came out of the blue). Then it buckets the time into 30 second buckets, since it could take several seconds to do a port scan of numerous ports. The eventstats command counts the number of distinct (<span style=\"font-family: 'Courier New';\">dc<\/span>) destination ports (<span style=\"font-family: 'Courier New';\">DPT<\/span>) that are scanned in each time bucket from the same source IP (<span style=\"font-family: 'Courier New';\">SRC<\/span>)\u00a0 and names that field PortsScanned. It then only includes results where the number of ports scanned is greater than 5: a single port is not a scan! Finally, it dedups the data and shows it in a nice table.<\/p>\n<p>The result is this:<\/p>\n<p><a href=\"http:\/\/www.nathanhunstad.com\/blog\/wp-content\/uploads\/2015\/03\/image.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border: 0px;\" title=\"image\" src=\"http:\/\/www.nathanhunstad.com\/blog\/wp-content\/uploads\/2015\/03\/image_thumb.png\" alt=\"image\" width=\"664\" height=\"221\" border=\"0\" \/><\/a><\/p>\n<p>A little dashboard work, and now I have a dashboard panel that includes a way to quickly change the time span:<\/p>\n<p><a href=\"http:\/\/www.nathanhunstad.com\/blog\/wp-content\/uploads\/2015\/03\/image1.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border: 0px;\" title=\"image\" src=\"http:\/\/www.nathanhunstad.com\/blog\/wp-content\/uploads\/2015\/03\/image_thumb1.png\" alt=\"image\" width=\"676\" height=\"189\" border=\"0\" \/><\/a><\/p>\n<p>As before, I could easily map this with the <span style=\"font-family: 'Courier New';\">iplocation<\/span> and <span style=\"font-family: 'Courier New';\">geostats<\/span> functions. Quick and easy!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It\u2019s been a while since I\u2019ve done some Splunk work on my home network, but lately I&#8217;ve been\u00a0thinking about port scans, specifically about reporting on port scans against my environment.\u00a0I\u2019m not terribly worried about people scanning my network since it is quite locked down, but why not check on it to see if anything interesting&hellip; <a class=\"more-link\" href=\"https:\/\/www.nathanhunstad.com\/blog\/2015\/03\/splunk-reporting-port-scans\/\">Continue reading <span class=\"screen-reader-text\">Splunk Reporting: Port Scans<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[127,19],"tags":[268,252],"class_list":["post-1158","post","type-post","status-publish","format-standard","hentry","category-security","category-tech-2","tag-port-scan","tag-splunk","entry"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"Setting up a Splunk report to show ports scan attempts against my network is quick and easy.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Nathan Hunstad\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.nathanhunstad.com\/blog\/2015\/03\/splunk-reporting-port-scans\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"The blog of Nathan Hunstad |\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Splunk Reporting: Port Scans | The blog of Nathan Hunstad\" \/>\n\t\t<meta property=\"og:description\" content=\"Setting up a Splunk report to show ports scan attempts against my network is quick and easy.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.nathanhunstad.com\/blog\/2015\/03\/splunk-reporting-port-scans\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.nathanhunstad.com\/blog\/wp-content\/uploads\/2023\/05\/facicon-stretched.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.nathanhunstad.com\/blog\/wp-content\/uploads\/2023\/05\/facicon-stretched.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"484\" \/>\n\t\t<meta property=\"og:image:height\" content=\"258\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2015-03-07T15:10:40+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2015-03-07T15:13:49+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Splunk Reporting: Port Scans | The blog of Nathan Hunstad\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Setting up a Splunk report to show ports scan attempts against my network is quick and easy.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.nathanhunstad.com\/blog\/wp-content\/uploads\/2023\/05\/facicon-stretched.jpg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/2015\\\/03\\\/splunk-reporting-port-scans\\\/#article\",\"name\":\"Splunk Reporting: Port Scans | The blog of Nathan Hunstad\",\"headline\":\"Splunk Reporting: Port Scans\",\"author\":{\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/author\\\/huns0004\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/#person\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/wp-content\\\/uploads\\\/2015\\\/03\\\/image_thumb.png\",\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/2015\\\/03\\\/splunk-reporting-port-scans\\\/#articleImage\",\"width\":664,\"height\":221},\"datePublished\":\"2015-03-07T09:10:40-06:00\",\"dateModified\":\"2015-03-07T09:13:49-06:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/2015\\\/03\\\/splunk-reporting-port-scans\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/2015\\\/03\\\/splunk-reporting-port-scans\\\/#webpage\"},\"articleSection\":\"Security, Tech, Port Scan, Splunk\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/2015\\\/03\\\/splunk-reporting-port-scans\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/category\\\/tech-2\\\/#listItem\",\"name\":\"Tech\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/category\\\/tech-2\\\/#listItem\",\"position\":2,\"name\":\"Tech\",\"item\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/category\\\/tech-2\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/2015\\\/03\\\/splunk-reporting-port-scans\\\/#listItem\",\"name\":\"Splunk Reporting: Port Scans\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/2015\\\/03\\\/splunk-reporting-port-scans\\\/#listItem\",\"position\":3,\"name\":\"Splunk Reporting: Port Scans\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/category\\\/tech-2\\\/#listItem\",\"name\":\"Tech\"}}]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/#person\",\"name\":\"Nathan Hunstad\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/2015\\\/03\\\/splunk-reporting-port-scans\\\/#personImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c5113ffdbe47c3095654b9158d4f067a549f1c82013a3f3c5dd7773d3f4b5be0?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Nathan Hunstad\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/author\\\/huns0004\\\/#author\",\"url\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/author\\\/huns0004\\\/\",\"name\":\"Nathan Hunstad\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/2015\\\/03\\\/splunk-reporting-port-scans\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c5113ffdbe47c3095654b9158d4f067a549f1c82013a3f3c5dd7773d3f4b5be0?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Nathan Hunstad\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/2015\\\/03\\\/splunk-reporting-port-scans\\\/#webpage\",\"url\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/2015\\\/03\\\/splunk-reporting-port-scans\\\/\",\"name\":\"Splunk Reporting: Port Scans | The blog of Nathan Hunstad\",\"description\":\"Setting up a Splunk report to show ports scan attempts against my network is quick and easy.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/2015\\\/03\\\/splunk-reporting-port-scans\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/author\\\/huns0004\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/author\\\/huns0004\\\/#author\"},\"datePublished\":\"2015-03-07T09:10:40-06:00\",\"dateModified\":\"2015-03-07T09:13:49-06:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/\",\"name\":\"The blog of Nathan Hunstad\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.nathanhunstad.com\\\/blog\\\/#person\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Splunk Reporting: Port Scans | The blog of Nathan Hunstad","description":"Setting up a Splunk report to show ports scan attempts against my network is quick and easy.","canonical_url":"https:\/\/www.nathanhunstad.com\/blog\/2015\/03\/splunk-reporting-port-scans\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.nathanhunstad.com\/blog\/2015\/03\/splunk-reporting-port-scans\/#article","name":"Splunk Reporting: Port Scans | The blog of Nathan Hunstad","headline":"Splunk Reporting: Port Scans","author":{"@id":"https:\/\/www.nathanhunstad.com\/blog\/author\/huns0004\/#author"},"publisher":{"@id":"https:\/\/www.nathanhunstad.com\/blog\/#person"},"image":{"@type":"ImageObject","url":"https:\/\/www.nathanhunstad.com\/blog\/wp-content\/uploads\/2015\/03\/image_thumb.png","@id":"https:\/\/www.nathanhunstad.com\/blog\/2015\/03\/splunk-reporting-port-scans\/#articleImage","width":664,"height":221},"datePublished":"2015-03-07T09:10:40-06:00","dateModified":"2015-03-07T09:13:49-06:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.nathanhunstad.com\/blog\/2015\/03\/splunk-reporting-port-scans\/#webpage"},"isPartOf":{"@id":"https:\/\/www.nathanhunstad.com\/blog\/2015\/03\/splunk-reporting-port-scans\/#webpage"},"articleSection":"Security, Tech, Port Scan, Splunk"},{"@type":"BreadcrumbList","@id":"https:\/\/www.nathanhunstad.com\/blog\/2015\/03\/splunk-reporting-port-scans\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.nathanhunstad.com\/blog#listItem","position":1,"name":"Home","item":"https:\/\/www.nathanhunstad.com\/blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.nathanhunstad.com\/blog\/category\/tech-2\/#listItem","name":"Tech"}},{"@type":"ListItem","@id":"https:\/\/www.nathanhunstad.com\/blog\/category\/tech-2\/#listItem","position":2,"name":"Tech","item":"https:\/\/www.nathanhunstad.com\/blog\/category\/tech-2\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.nathanhunstad.com\/blog\/2015\/03\/splunk-reporting-port-scans\/#listItem","name":"Splunk Reporting: Port Scans"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.nathanhunstad.com\/blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.nathanhunstad.com\/blog\/2015\/03\/splunk-reporting-port-scans\/#listItem","position":3,"name":"Splunk Reporting: Port Scans","previousItem":{"@type":"ListItem","@id":"https:\/\/www.nathanhunstad.com\/blog\/category\/tech-2\/#listItem","name":"Tech"}}]},{"@type":"Person","@id":"https:\/\/www.nathanhunstad.com\/blog\/#person","name":"Nathan Hunstad","image":{"@type":"ImageObject","@id":"https:\/\/www.nathanhunstad.com\/blog\/2015\/03\/splunk-reporting-port-scans\/#personImage","url":"https:\/\/secure.gravatar.com\/avatar\/c5113ffdbe47c3095654b9158d4f067a549f1c82013a3f3c5dd7773d3f4b5be0?s=96&d=mm&r=g","width":96,"height":96,"caption":"Nathan Hunstad"}},{"@type":"Person","@id":"https:\/\/www.nathanhunstad.com\/blog\/author\/huns0004\/#author","url":"https:\/\/www.nathanhunstad.com\/blog\/author\/huns0004\/","name":"Nathan Hunstad","image":{"@type":"ImageObject","@id":"https:\/\/www.nathanhunstad.com\/blog\/2015\/03\/splunk-reporting-port-scans\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/c5113ffdbe47c3095654b9158d4f067a549f1c82013a3f3c5dd7773d3f4b5be0?s=96&d=mm&r=g","width":96,"height":96,"caption":"Nathan Hunstad"}},{"@type":"WebPage","@id":"https:\/\/www.nathanhunstad.com\/blog\/2015\/03\/splunk-reporting-port-scans\/#webpage","url":"https:\/\/www.nathanhunstad.com\/blog\/2015\/03\/splunk-reporting-port-scans\/","name":"Splunk Reporting: Port Scans | The blog of Nathan Hunstad","description":"Setting up a Splunk report to show ports scan attempts against my network is quick and easy.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.nathanhunstad.com\/blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.nathanhunstad.com\/blog\/2015\/03\/splunk-reporting-port-scans\/#breadcrumblist"},"author":{"@id":"https:\/\/www.nathanhunstad.com\/blog\/author\/huns0004\/#author"},"creator":{"@id":"https:\/\/www.nathanhunstad.com\/blog\/author\/huns0004\/#author"},"datePublished":"2015-03-07T09:10:40-06:00","dateModified":"2015-03-07T09:13:49-06:00"},{"@type":"WebSite","@id":"https:\/\/www.nathanhunstad.com\/blog\/#website","url":"https:\/\/www.nathanhunstad.com\/blog\/","name":"The blog of Nathan Hunstad","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.nathanhunstad.com\/blog\/#person"}}]},"og:locale":"en_US","og:site_name":"The blog of Nathan Hunstad |","og:type":"article","og:title":"Splunk Reporting: Port Scans | The blog of Nathan Hunstad","og:description":"Setting up a Splunk report to show ports scan attempts against my network is quick and easy.","og:url":"https:\/\/www.nathanhunstad.com\/blog\/2015\/03\/splunk-reporting-port-scans\/","og:image":"https:\/\/www.nathanhunstad.com\/blog\/wp-content\/uploads\/2023\/05\/facicon-stretched.jpg","og:image:secure_url":"https:\/\/www.nathanhunstad.com\/blog\/wp-content\/uploads\/2023\/05\/facicon-stretched.jpg","og:image:width":484,"og:image:height":258,"article:published_time":"2015-03-07T15:10:40+00:00","article:modified_time":"2015-03-07T15:13:49+00:00","twitter:card":"summary","twitter:title":"Splunk Reporting: Port Scans | The blog of Nathan Hunstad","twitter:description":"Setting up a Splunk report to show ports scan attempts against my network is quick and easy.","twitter:image":"https:\/\/www.nathanhunstad.com\/blog\/wp-content\/uploads\/2023\/05\/facicon-stretched.jpg"},"aioseo_meta_data":{"post_id":"1158","title":"Splunk Reporting: Port Scans | #site_title","description":"Setting up a Splunk report to show ports scan attempts against my network is quick and easy.","keywords":[{"label":"Splunk","value":"Splunk"},{"label":"Port Scans","value":"Port Scans"},{"label":"Security","value":"Security"}],"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"location":null,"local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2021-03-15 19:32:49","updated":"2025-06-04 06:04:28","seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.nathanhunstad.com\/blog\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.nathanhunstad.com\/blog\/category\/tech-2\/\" title=\"Tech\">Tech<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tSplunk Reporting: Port Scans\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.nathanhunstad.com\/blog"},{"label":"Tech","link":"https:\/\/www.nathanhunstad.com\/blog\/category\/tech-2\/"},{"label":"Splunk Reporting: Port Scans","link":"https:\/\/www.nathanhunstad.com\/blog\/2015\/03\/splunk-reporting-port-scans\/"}],"_links":{"self":[{"href":"https:\/\/www.nathanhunstad.com\/blog\/wp-json\/wp\/v2\/posts\/1158","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.nathanhunstad.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.nathanhunstad.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.nathanhunstad.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.nathanhunstad.com\/blog\/wp-json\/wp\/v2\/comments?post=1158"}],"version-history":[{"count":2,"href":"https:\/\/www.nathanhunstad.com\/blog\/wp-json\/wp\/v2\/posts\/1158\/revisions"}],"predecessor-version":[{"id":1161,"href":"https:\/\/www.nathanhunstad.com\/blog\/wp-json\/wp\/v2\/posts\/1158\/revisions\/1161"}],"wp:attachment":[{"href":"https:\/\/www.nathanhunstad.com\/blog\/wp-json\/wp\/v2\/media?parent=1158"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.nathanhunstad.com\/blog\/wp-json\/wp\/v2\/categories?post=1158"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.nathanhunstad.com\/blog\/wp-json\/wp\/v2\/tags?post=1158"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}