<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Add-on for Nessus: Why am I unable to pull Nessus data after configuring the API key? &amp;quot;ParseError: not well-formed (invalid token)&amp;quot; in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Nessus-Why-am-I-unable-to-pull-Nessus-data/m-p/286948#M34149</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I installed Splunk Add-on for Nessus on a search head and configured the API key for Nessus, but I'm not seeing any data.  Running the debug I get the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2015-12-21 14:32:24,525 ERROR pid=2708 tid=MainThread file=nessus.py:get_nessus_modinput_configs:157 | Traceback (most recent call last):
  File "C:\Program Files\Splunk\etc\apps\Splunk_TA_nessus\bin\nessus.py", line 135, in get_nessus_modinput_configs
    config.remove_expired_credentials()
  File "C:\Program Files\Splunk\etc\apps\Splunk_TA_nessus\bin\nessus_config.py", line 142, in remove_expired_credentials
    creds = self._get_raw_stanza(stanza_type="cred", check_exist=False)
  File "C:\Program Files\Splunk\etc\apps\Splunk_TA_nessus\bin\nessus_config.py", line 262, in _get_raw_stanza
    stanza = self.cred_mgr.get_clear_password(stanza_name)
  File "C:\Program Files\Splunk\etc\apps\Splunk_TA_nessus\bin\splunktalib\credentials.py", line 159, in get_clear_password
    return self._get_credentials("clear_password", name)
  File "C:\Program Files\Splunk\etc\apps\Splunk_TA_nessus\bin\splunktalib\credentials.py", line 179, in _get_credentials
    passwords = xdp.parse_conf_xml_dom(content)
  File "C:\Program Files\Splunk\etc\apps\Splunk_TA_nessus\bin\splunktalib\common\xml_dom_parser.py", line 19, in parse_conf_xml_dom
    xml_conf = et.fromstring(xml_content)
  File "&amp;lt;string&amp;gt;", line 124, in XML
ParseError: not well-formed (invalid token): line 32, column 38
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any help is appreciated.&lt;/P&gt;

&lt;P&gt;-Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 21 Dec 2015 23:49:12 GMT</pubDate>
    <dc:creator>tungntran</dc:creator>
    <dc:date>2015-12-21T23:49:12Z</dc:date>
    <item>
      <title>Splunk Add-on for Nessus: Why am I unable to pull Nessus data after configuring the API key? "ParseError: not well-formed (invalid token)"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Nessus-Why-am-I-unable-to-pull-Nessus-data/m-p/286948#M34149</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I installed Splunk Add-on for Nessus on a search head and configured the API key for Nessus, but I'm not seeing any data.  Running the debug I get the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2015-12-21 14:32:24,525 ERROR pid=2708 tid=MainThread file=nessus.py:get_nessus_modinput_configs:157 | Traceback (most recent call last):
  File "C:\Program Files\Splunk\etc\apps\Splunk_TA_nessus\bin\nessus.py", line 135, in get_nessus_modinput_configs
    config.remove_expired_credentials()
  File "C:\Program Files\Splunk\etc\apps\Splunk_TA_nessus\bin\nessus_config.py", line 142, in remove_expired_credentials
    creds = self._get_raw_stanza(stanza_type="cred", check_exist=False)
  File "C:\Program Files\Splunk\etc\apps\Splunk_TA_nessus\bin\nessus_config.py", line 262, in _get_raw_stanza
    stanza = self.cred_mgr.get_clear_password(stanza_name)
  File "C:\Program Files\Splunk\etc\apps\Splunk_TA_nessus\bin\splunktalib\credentials.py", line 159, in get_clear_password
    return self._get_credentials("clear_password", name)
  File "C:\Program Files\Splunk\etc\apps\Splunk_TA_nessus\bin\splunktalib\credentials.py", line 179, in _get_credentials
    passwords = xdp.parse_conf_xml_dom(content)
  File "C:\Program Files\Splunk\etc\apps\Splunk_TA_nessus\bin\splunktalib\common\xml_dom_parser.py", line 19, in parse_conf_xml_dom
    xml_conf = et.fromstring(xml_content)
  File "&amp;lt;string&amp;gt;", line 124, in XML
ParseError: not well-formed (invalid token): line 32, column 38
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any help is appreciated.&lt;/P&gt;

&lt;P&gt;-Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2015 23:49:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Nessus-Why-am-I-unable-to-pull-Nessus-data/m-p/286948#M34149</guid>
      <dc:creator>tungntran</dc:creator>
      <dc:date>2015-12-21T23:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Nessus: Why am I unable to pull Nessus data after configuring the API key? "ParseError: not well-formed (invalid token)"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Nessus-Why-am-I-unable-to-pull-Nessus-data/m-p/286949#M34150</link>
      <description>&lt;P&gt;Can you make sure the two keys are both surrounded by single quotes?  &lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2015 00:59:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Nessus-Why-am-I-unable-to-pull-Nessus-data/m-p/286949#M34150</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2015-12-22T00:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Nessus: Why am I unable to pull Nessus data after configuring the API key? "ParseError: not well-formed (invalid token)"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Nessus-Why-am-I-unable-to-pull-Nessus-data/m-p/286950#M34151</link>
      <description>&lt;P&gt;Thanks for responding, adding the single quote didn't help. I'm getting the same error.  &lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2015 16:47:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Nessus-Why-am-I-unable-to-pull-Nessus-data/m-p/286950#M34151</guid>
      <dc:creator>tungntran</dc:creator>
      <dc:date>2015-12-23T16:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Nessus: Why am I unable to pull Nessus data after configuring the API key? "ParseError: not well-formed (invalid token)"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Nessus-Why-am-I-unable-to-pull-Nessus-data/m-p/286951#M34152</link>
      <description>&lt;P&gt;We are seeing this in Linux splunk also. Interesting thing, I can take the entirety of Splunk_TA_nessus in /opt/splunk/etc/apps on the search head it's failing on to another search head, restart splunk and it works on two other search heads.&lt;/P&gt;

&lt;P&gt;The only difference being that one search head has the Enterprise Security app on it, and the others do not.&lt;/P&gt;

&lt;P&gt;This is the 4.0.0 version exhibiting the behavior for us. Our splunk level is 6.2.5 and correspondingly supported Enterprise Security app version 3.31&lt;/P&gt;

&lt;P&gt;We've examined permissions between the working and not working deployments and nothing is obvious. &lt;/P&gt;

&lt;P&gt;We'd like this on the same SH as Enterprise Security if possible.&lt;/P&gt;

&lt;P&gt;Adding my voice to this in hopes that the above information helps connect some dots.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:21:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Nessus-Why-am-I-unable-to-pull-Nessus-data/m-p/286951#M34152</guid>
      <dc:creator>Admiral_Marith</dc:creator>
      <dc:date>2020-09-29T08:21:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Nessus: Why am I unable to pull Nessus data after configuring the API key? "ParseError: not well-formed (invalid token)"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Nessus-Why-am-I-unable-to-pull-Nessus-data/m-p/286952#M34153</link>
      <description>&lt;P&gt;This looks like it needs more than casual attention to troubleshoot. Can someone in this thread please open a support ticket so we can diagnose?&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jan 2016 21:00:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Nessus-Why-am-I-unable-to-pull-Nessus-data/m-p/286952#M34153</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2016-01-24T21:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Nessus: Why am I unable to pull Nessus data after configuring the API key? "ParseError: not well-formed (invalid token)"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Nessus-Why-am-I-unable-to-pull-Nessus-data/m-p/286953#M34154</link>
      <description>&lt;P&gt;Same error for me with Splunk_TA_Nessus version 4.0 on a search head with Enterprise Security app version 4.&lt;/P&gt;

&lt;P&gt;Please can you help us?&lt;BR /&gt;
Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:44:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Nessus-Why-am-I-unable-to-pull-Nessus-data/m-p/286953#M34154</guid>
      <dc:creator>marcellomotta</dc:creator>
      <dc:date>2020-09-29T08:44:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Nessus: Why am I unable to pull Nessus data after configuring the API key? "ParseError: not well-formed (invalid token)"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Nessus-Why-am-I-unable-to-pull-Nessus-data/m-p/286954#M34155</link>
      <description>&lt;P&gt;please come back and post a workaround or solution when one is available. &lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2016 17:07:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Nessus-Why-am-I-unable-to-pull-Nessus-data/m-p/286954#M34155</guid>
      <dc:creator>piebob</dc:creator>
      <dc:date>2016-02-11T17:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Nessus: Why am I unable to pull Nessus data after configuring the API key? "ParseError: not well-formed (invalid token)"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Nessus-Why-am-I-unable-to-pull-Nessus-data/m-p/286955#M34156</link>
      <description>&lt;P&gt;I'm receiving the same error. A ticket has been opened. &lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2016 15:44:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Nessus-Why-am-I-unable-to-pull-Nessus-data/m-p/286955#M34156</guid>
      <dc:creator>sprooit</dc:creator>
      <dc:date>2016-02-18T15:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Nessus: Why am I unable to pull Nessus data after configuring the API key? "ParseError: not well-formed (invalid token)"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Nessus-Why-am-I-unable-to-pull-Nessus-data/m-p/286956#M34157</link>
      <description>&lt;P&gt;I have managed to resolve by configuring the deploy server to not deploy the same access_key and secret_key on the clients but only the application/configuration.&lt;BR /&gt;
Following, the keys have been updated manually on all the clients.&lt;/P&gt;

&lt;P&gt;Thank you very much&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:50:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Nessus-Why-am-I-unable-to-pull-Nessus-data/m-p/286956#M34157</guid>
      <dc:creator>marcellomotta</dc:creator>
      <dc:date>2020-09-29T08:50:15Z</dc:date>
    </item>
  </channel>
</rss>

