<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Add-on for Tenable: Why do I receive &amp;quot;Unable to process Vuln Query&amp;quot; error message? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Why-do-I-receive-quot-Unable-to/m-p/343022#M41449</link>
    <description>&lt;P&gt;Worked with Tenable support on another issue (frequent timeouts when using the UI) and they had me adjust the "max_execution_time" value in /opt/sc/support/etc/php.ini:&lt;/P&gt;

&lt;P&gt;# Backup the PHP file:&lt;BR /&gt;
$ cp /opt/sc/support/etc/php.ini /opt/sc/support/etc/php.ini.bk&lt;/P&gt;

&lt;P&gt;# Edit the PHP.ini file&lt;BR /&gt;
$ vi /opt/sc/support/etc/php.ini &lt;/P&gt;

&lt;P&gt;Scroll down to the max_execution_time setting and double/triple the value that is in there. The default is 30s so I increased mine to 90s. Save the file then restart SecurityCenter.&lt;/P&gt;

&lt;P&gt;Since this change I've been able to pull all scan results into Splunk.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 14:13:44 GMT</pubDate>
    <dc:creator>Blu3fish</dc:creator>
    <dc:date>2020-09-29T14:13:44Z</dc:date>
    <item>
      <title>Splunk Add-on for Tenable: Why do I receive "Unable to process Vuln Query" error message?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Why-do-I-receive-quot-Unable-to/m-p/343016#M41443</link>
      <description>&lt;P&gt;Using v5.1.1 of the Splunk Add-on for Tenable (&lt;A href="https://splunkbase.splunk.com/app/1710/"&gt;https://splunkbase.splunk.com/app/1710/&lt;/A&gt;) to pull scan results from Security Center (5.4.4). I'm receiving the occasional scan result but not all scan results and am seeing the following log repeated over and over in index=_internal sourcetype=tenable:sc:log:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2017-03-08 15:51:57,258 +0000 log_level=WARNING, pid=20668, tid=Thread-5, file=ta_tenable_sc_data_collector.py, func_name=_pre_process_ckpt, code_line_no=284 | [stanza_name="securitycenterserver" data="sc_vulnerability" server="securitycenterserver"] error_msg=Unable to process Vuln Query.
SecurityCenter could not process the vulnerability filter string (SC_ROOT=/opt/sc /opt/sc/bin/showvulns-individual  +orgid "1" +groupid "0" +tool 'listvuln' +datedir "2017-03-08" +scanid '1234' +view 'all' +startoffset '0' +endoffset '0' +repository "1"  -acceptRisk).
11^list^0^0^-1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The scanid does change per event which accurately reflects the scanids from security center that aren't being ingested.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2017 17:43:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Why-do-I-receive-quot-Unable-to/m-p/343016#M41443</guid>
      <dc:creator>Blu3fish</dc:creator>
      <dc:date>2017-03-08T17:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Tenable: Why do I receive "Unable to process Vuln Query" error message?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Why-do-I-receive-quot-Unable-to/m-p/343017#M41444</link>
      <description>&lt;P&gt;Seems the log pasted is broken, would you please provide the raw logs?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 01:37:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Why-do-I-receive-quot-Unable-to/m-p/343017#M41444</guid>
      <dc:creator>hozhang_splunk</dc:creator>
      <dc:date>2017-03-10T01:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Tenable: Why do I receive "Unable to process Vuln Query" error message?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Why-do-I-receive-quot-Unable-to/m-p/343018#M41445</link>
      <description>&lt;P&gt;2017-03-08 15:51:57,258 +0000 log_level=WARNING, pid=20668, tid=Thread-5, file=ta_tenable_sc_data_collector.py, func_name=_pre_process_ckpt, code_line_no=284 | [stanza_name="securitycenterserver" data="sc_vulnerability" server="securitycenterserver"] error_msg=Unable to process Vuln Query.&lt;BR /&gt;
SecurityCenter could not process the vulnerability filter string (SC_ROOT=/opt/sc /opt/sc/bin/showvulns-individual  +orgid "1" +groupid "0" +tool 'listvuln' +datedir "2017-03-08" +scanid '2275' +view 'all' +startoffset '0' +endoffset '0' +repository "1"  -acceptRisk).&lt;BR /&gt;
11^list^0^0^-1&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:10:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Why-do-I-receive-quot-Unable-to/m-p/343018#M41445</guid>
      <dc:creator>Blu3fish</dc:creator>
      <dc:date>2020-09-29T13:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Tenable: Why do I receive "Unable to process Vuln Query" error message?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Why-do-I-receive-quot-Unable-to/m-p/343019#M41446</link>
      <description>&lt;P&gt;I am having this same problem too.  Has anyone been able to figure this out?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 16:43:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Why-do-I-receive-quot-Unable-to/m-p/343019#M41446</guid>
      <dc:creator>lamars79</dc:creator>
      <dc:date>2017-03-24T16:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Tenable: Why do I receive "Unable to process Vuln Query" error message?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Why-do-I-receive-quot-Unable-to/m-p/343020#M41447</link>
      <description>&lt;P&gt;This seems an issue at Tenable side. &lt;BR /&gt;
&lt;A href="https://community.tenable.com/thread/9403"&gt;https://community.tenable.com/thread/9403&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 03:27:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Why-do-I-receive-quot-Unable-to/m-p/343020#M41447</guid>
      <dc:creator>hozhang_splunk</dc:creator>
      <dc:date>2017-03-27T03:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Tenable: Why do I receive "Unable to process Vuln Query" error message?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Why-do-I-receive-quot-Unable-to/m-p/343021#M41448</link>
      <description>&lt;P&gt;Did anyone find a fix for this issue? I am having the same exact error message&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 21:45:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Why-do-I-receive-quot-Unable-to/m-p/343021#M41448</guid>
      <dc:creator>shirishkamat84</dc:creator>
      <dc:date>2017-05-09T21:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Tenable: Why do I receive "Unable to process Vuln Query" error message?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Why-do-I-receive-quot-Unable-to/m-p/343022#M41449</link>
      <description>&lt;P&gt;Worked with Tenable support on another issue (frequent timeouts when using the UI) and they had me adjust the "max_execution_time" value in /opt/sc/support/etc/php.ini:&lt;/P&gt;

&lt;P&gt;# Backup the PHP file:&lt;BR /&gt;
$ cp /opt/sc/support/etc/php.ini /opt/sc/support/etc/php.ini.bk&lt;/P&gt;

&lt;P&gt;# Edit the PHP.ini file&lt;BR /&gt;
$ vi /opt/sc/support/etc/php.ini &lt;/P&gt;

&lt;P&gt;Scroll down to the max_execution_time setting and double/triple the value that is in there. The default is 30s so I increased mine to 90s. Save the file then restart SecurityCenter.&lt;/P&gt;

&lt;P&gt;Since this change I've been able to pull all scan results into Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:13:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Why-do-I-receive-quot-Unable-to/m-p/343022#M41449</guid>
      <dc:creator>Blu3fish</dc:creator>
      <dc:date>2020-09-29T14:13:44Z</dc:date>
    </item>
  </channel>
</rss>

