◼️
General Knowledge
  • Introduction
  • Building a Home Lab
  • Certification Roadmap
  • Basics
    • Basic Networking
    • Basic Gigamon Configuration
  • Firewalls
    • PFSense
    • Cisco ASA
  • Hardware Setup and Device Networking
    • Cisco Device
    • MaxVision Servers
    • Gigamon
  • Reporting
    • Network Activity Report (NAR)
    • Network Change Request (NCR)
    • Redmine
  • DCO Tools
    • Splunk
      • Threat Hunting with Splunk
    • Security Onion 2.4
      • Threat Hunting with Security Onion
    • OsQuery
  • Methodology
    • Gather Information
    • Gather Documents
    • Prepare Equipment and Team Procedures
    • Conduct Network Reconnaissance
    • MITTRE ATT&CK Framework
    • Considerations when Recommending Remedial Action
    • Document Everything
    • Defensive Cyber Operations Checklist
  • Requirements
    • Power Requirements
    • Port Density Requirements
    • Opened Port Requirements
  • Building a Virtual Testing Environment
    • Identify Requirements
    • Gather Equipment and tools
    • Initial Draft
    • Building the Environment
    • Example
Powered by GitBook
On this page
  • Splunk
  • Elastic Agent
  • OsQuery
  • Syslog
  1. Requirements

Opened Port Requirements

Splunk

  • 9997 Universal Forwarders

  • 8089 Deployment Server

  • 8000 Web Access

Elastic Agent

  • 8220 Elastic Agent Control

  • 5055 Elastic Agent Data

  • 5044 Beats

  • 3765 Endgame

OsQuery

  • 8090 - Osquery Agent

Syslog

  • 514 - Syslog Logs

PreviousPort Density RequirementsNextIdentify Requirements

Last updated 2 years ago