Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Splunk Add-on for Nessu: Why is my search not retrieving all events from the Nessus scan?

$
0
0
Wondering if anyone else is seeing this problem. I configured the Splunk add-on for Nessus without any problems. I'm able to search for Nessus events in Splunk, however, I'm not seeing all the events I'm expecting to see. First I ran a host discovery scan in Nessus. I then ran this search in Splunk to only pull the events from that scan: sourcetype=nessus:scan name = "Host discovery scan" The Nessus scan discovered 294 hosts, yet the Splunk search only returned 248 hosts. I've racked my brains trying to figure out why but came up short. Any ideas what could be happening here? ![alt text][1] [1]: /storage/temp/92174-splunk.jpg

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>