

The following is an example of the contents of a PR-PIDS log file:Īvailability and description of the Port Reporter tool The PR-PIDS log file contains detailed information about ports, processes, related modules, and the user account the process uses to run. On Windows 2000-based computers that do not support port-to-process mapping, the Port Reporter service lists the data by using the following format:ĭate,time,protocol,local port,local IP address,remote port,remote IP addressĠ4/6/11,13:15:2,TCP,1029,6 2.130.153.

The data is listed by using a comma-separated value (csv) format as follows:ĭate,time,protocol,local port,local IP address,remote port,remote IP address,PID,module,user context The PR-PORTS log file contains summary data about TCP and UDP port activity on the computer. The following is an example of the contents of a PR-INITIAL log file on a Windows XP-based computer that was created when the Port Reporter service started The user context that each process is running under is also logged.

The PR-INITIAL log file contains data that the Port Reporter service collects about the ports, processes, and modules that run on the computer when the Port Reporter service is started. Your Ports and the process's using them will now be added to C:\WINDOWS\SYSTEM32\Logfil es\PortRep orter in real time listed as follows Locate the Port reporter service and double click it, select Start. Unzip it to a folder and run the Pr-Setup.exe program. Download and unzip the Port Reporter tool from displaylang=en&familyid=69BA779B-BAE9-4243-B9D6-63E62B4BCD2E&displaylang=en
