Hello,
I have Splunk Enterprise 6.2.5 running in a distributed environment and I can't seem to get the Nessus Add-on 4.0.0 to work. I have it installed on one of my search heads and configured as follows but I am not getting any data written to the nessus index. Am I missing something? Thanks in advance for any help.
**inputs.conf**
[nessus://nessus_scan]
interval = 86400
url = https://myserver.myco.com:8834
access_key = ********
secret_key = ********
start_date = 2015/01/01
page_size = 1000
metric = nessus_scan
batch_size = 100000
index = nessus
[nessus://nessus_plugin]
interval = 604800
url = https://myserver.myco.com:8834
access_key = ********
secret_key = ********
start_date = 2015/01/01
page_size = 1000
metric = nessus_plugin
batch_size = 100000
index = nessus
**ta_nessus.log**
2015-11-20 10:15:23,386 INFO pid=8117 tid=MainThread file=nessus.py:main:260 | Start nessus TA
2015-11-20 10:15:23,525 INFO pid=8121 tid=MainThread file=nessus.py:main:260 | Start nessus TA
2015-11-20 10:15:23,589 INFO pid=8117 tid=MainThread file=nessus_config.py:get_nessus_conf:80 | Try to get encrypted proxy username & password
2015-11-20 10:15:23,590 INFO pid=8117 tid=MainThread file=nessus_config.py:update_nessus_conf:66 | Update nessus.conf
2015-11-20 10:15:23,590 INFO pid=8117 tid=MainThread file=nessus_config.py:_encrypt_nessus_conf:198 | Encrypt the proxy username & password
2015-11-20 10:15:23,590 INFO pid=8117 tid=MainThread file=nessus_config.py:_encrypt_nessus_conf:206 | Proxy username is empty. Try to delete the encrypted proxy username & password
2015-11-20 10:15:23,657 INFO pid=8121 tid=MainThread file=nessus_config.py:get_nessus_conf:80 | Try to get encrypted proxy username & password
2015-11-20 10:15:23,657 INFO pid=8121 tid=MainThread file=nessus_config.py:update_nessus_conf:66 | Update nessus.conf
2015-11-20 10:15:23,657 INFO pid=8121 tid=MainThread file=nessus_config.py:_encrypt_nessus_conf:198 | Encrypt the proxy username & password
2015-11-20 10:15:23,657 INFO pid=8121 tid=MainThread file=nessus_config.py:_encrypt_nessus_conf:206 | Proxy username is empty. Try to delete the encrypted proxy username & password
2015-11-20 10:15:23,667 INFO pid=8117 tid=MainThread file=nessus.py:get_nessus_modinput_configs:142 | Set loglevel to WARN
2015-11-20 10:15:23,738 INFO pid=8121 tid=MainThread file=nessus.py:get_nessus_modinput_configs:142 | Set loglevel to WARN
**/opt/splunk/var/lib/splunk/modinputs/nessus/nessus_scan_nessus_scan.ckpt**
{
"https://myserver.myco.com:8834": {
"start_date": "2015/01/01",
"scans": {
"80": {
"hosts": [],
"history_id": 81
},
"74": {
"hosts": [],
"history_id": 75
},
"5": {
"hosts": [],
"history_id": 6
},
"12": {
"hosts": [],
"history_id": 149
},
"126": {
"hosts": [],
"history_id": 154
},
"8": {
"hosts": [],
"history_id": 76
},
"70": {
"hosts": [],
"history_id": 147
}
}
}
}
↧