I'm having an issue where Splunk is indexing running Nessus scans despite having changed the `index_events_for_unsuccessful_scans` option to `0` in Splunk_TA_Nessus/local/nessus.conf. I've tried everything I can think of, but the issue persists.
I've restarted Splunk, deleted and recreated the input, restarted the machine it's running on, edited the default version of nessus.conf, and deleted and reinstalled the Add-On. Despite this, I'm still getting the incomplete scan data.
Has anyone else had this problem and been able to fix it? I'm using the brand new release of the add-on (which is otherwise great, by the way).
↧