# \[Population Job\]: port scanner

**URL:** <https://discuss.elastic.co/t/population-job-port-scanner/260870>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-machine-learning\
**Created:** [January 12, 2021, 4:48pm UTC](https://discuss.elastic.co/t/population-job-port-scanner/260870 "2021-01-12T16:48:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![TheHunter1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thehunter1/32/80190_2.png) [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Post date:** [January 12, 2021, 4:48pm UTC](https://discuss.elastic.co/t/population-job-port-scanner/260870/1 "2021-01-12T16:48:43Z")

</div>

Hello everybody,

I would like to create a machine learning job to detect port scanner  
so I have configured my job like that:

**Job Type:** Population  
**Population field:** destination.ip  
**Add metric:** Distinct count(destination.port)  
**Influencers:** I have tried source.ip alone and then destination.ip alone and then both of them

and I got a result like that:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/7/8745f1340d7f75d82e7fd107c280cd69b972b1a1.png)

The problem is that I am getting just the `destination.ip`

for me I would like to know the `source.ip` which is scanning my machines and the `destination.ip` to know which machine is scanned.

Could you please tell me how I have to configure my Machine Learning job

Thanks

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [January 13, 2021, 3:38pm UTC](https://discuss.elastic.co/t/population-job-port-scanner/260870/2 "2021-01-13T15:38:05Z")

</div>

The config, and having both `source.ip` and `destination.ip` as influencers also is recommended. If you're not seeing certain `source.ip`s showing up as influencers, then basically that means that there isn't a significant single IP that is dominating and exhibiting that kind of behavior. If a certain `destination.ip` has a highly unusual number of ports being scanned, then it is not unimaginable that many `source.ip`s did that.

You could contrive an anomaly that you want to detect by allowing the ML job to learn for a while, then artificially created a port scan from a single device and see if the anomaly is reported as you expect.

---

<div class="post-metadata">

**Author:** ![TheHunter1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thehunter1/32/80190_2.png) [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Post date:** [January 13, 2021, 4:51pm UTC](https://discuss.elastic.co/t/population-job-port-scanner/260870/3 "2021-01-13T16:51:23Z")

</div>

I changed the index and I tried it with the `packetbeat-*` index and then scanned a machine where packetbeat is installed, and the machine learninig job worked perfectly

I think that the job didn't work with my firewall logs cause there are a lot of machine that are scanning my network, so the job is learninig while the machines are scanning, so it will consider that as a normal trafic ☹

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 10, 2021, 4:51pm UTC](https://discuss.elastic.co/t/population-job-port-scanner/260870/4 "2021-02-10T16:51:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
