<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Add-on for Tenable: Using add-on without a heavy forwarder in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Using-add-on-without-a-heavy-forwarder/m-p/357320#M43268</link>
    <description>&lt;P&gt;Our environment contains: &lt;BR /&gt;
Nessus Pro Vulnerability Scanner 6.5.6 (less than 1000 systems scanned)&lt;BR /&gt;
Splunk Enterprise 6.5.3 &lt;BR /&gt;
      Search Heads&lt;BR /&gt;
      Enterprise Security&lt;BR /&gt;
      Indexes&lt;BR /&gt;
      Deployment Server&lt;BR /&gt;
      Universal Forwarders&lt;/P&gt;

&lt;P&gt;I believe Nessus 6.5.6 still contains the REST API functionality. If I can get away with a Universal Forwarder, I would prefer that for now. Thanks for the help!&lt;/P&gt;</description>
    <pubDate>Wed, 27 Dec 2017 15:02:21 GMT</pubDate>
    <dc:creator>rsanders30</dc:creator>
    <dc:date>2017-12-27T15:02:21Z</dc:date>
    <item>
      <title>Splunk Add-on for Tenable: Using add-on without a heavy forwarder</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Using-add-on-without-a-heavy-forwarder/m-p/357317#M43265</link>
      <description>&lt;P&gt;So I've been going through the documentation for the Nessus Add-on. It states that you will need to install the add-on on a Heavy Forwarder, however, our environment does not contain one. Our Nessus Pro Vulnerability Scanner sits on a Windows Server. I did see that within the add-on there is an inputs.conf.windows, but doesn't seem to be any different than the inputs.conf. What is the best way to approach this? &lt;/P&gt;</description>
      <pubDate>Tue, 26 Dec 2017 21:14:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Using-add-on-without-a-heavy-forwarder/m-p/357317#M43265</guid>
      <dc:creator>rsanders30</dc:creator>
      <dc:date>2017-12-26T21:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Tenable: Using add-on without a heavy forwarder</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Using-add-on-without-a-heavy-forwarder/m-p/357318#M43266</link>
      <description>&lt;P&gt;Hi @rsanders30,&lt;/P&gt;

&lt;P&gt;Yes, there is a minor difference between inputs.conf and inputs.conf.windows. But if this difference only useful to you if you are using Nessus 5.X. For "Splunk Add-on for Tenable" installation, can you please share basic details of your Splunk &amp;amp; Nessus instance?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2017 10:17:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Using-add-on-without-a-heavy-forwarder/m-p/357318#M43266</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2017-12-27T10:17:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Tenable: Using add-on without a heavy forwarder</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Using-add-on-without-a-heavy-forwarder/m-p/357319#M43267</link>
      <description>&lt;P&gt;Just to save you some time (and possibly pain) - what version of Nessus pro are you using?&lt;/P&gt;

&lt;P&gt;The good people at Tenable have recently changed Nessus pro and disabled the REST APIs which the TA makes use of to extract scan results.&lt;/P&gt;

&lt;P&gt;If you are running an older version, stay there, if you are running 7x, there is currently  no programmatic way to extract scan data into a format Splunk can consume.&lt;/P&gt;

&lt;P&gt;(See: &lt;A href="https://answers.splunk.com/answers/598658/splunk-add-on-for-tenable-support-for-nessus-profe.html"&gt;https://answers.splunk.com/answers/598658/splunk-add-on-for-tenable-support-for-nessus-profe.html&lt;/A&gt;)&lt;/P&gt;

&lt;P&gt;The future looks a bit bleak for Splunk &amp;amp; Nessus Pro users. Tenable are trying to guide people to either Security Center or Tenable.IO which still supports the REST API. &lt;/P&gt;

&lt;P&gt;The Splunk Add-on for Tenable is designed to connect to Nessus SC, over the restAPi - which is why it is suggested to use an HF for this (as it can be quite heavy if you have a lot of scan results) it is not picking up local files in this configuration.&lt;/P&gt;

&lt;P&gt;If you are running the older Nessus Pro then the scripts in the package can be used to extract results from your scanner - there is no reason why you cant run these on your nessus box if you wish, but I think you will need a full heavy forwarder rather than a UF, because it relies on the python interpreter.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2017 10:40:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Using-add-on-without-a-heavy-forwarder/m-p/357319#M43267</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-12-27T10:40:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Tenable: Using add-on without a heavy forwarder</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Using-add-on-without-a-heavy-forwarder/m-p/357320#M43268</link>
      <description>&lt;P&gt;Our environment contains: &lt;BR /&gt;
Nessus Pro Vulnerability Scanner 6.5.6 (less than 1000 systems scanned)&lt;BR /&gt;
Splunk Enterprise 6.5.3 &lt;BR /&gt;
      Search Heads&lt;BR /&gt;
      Enterprise Security&lt;BR /&gt;
      Indexes&lt;BR /&gt;
      Deployment Server&lt;BR /&gt;
      Universal Forwarders&lt;/P&gt;

&lt;P&gt;I believe Nessus 6.5.6 still contains the REST API functionality. If I can get away with a Universal Forwarder, I would prefer that for now. Thanks for the help!&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2017 15:02:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Using-add-on-without-a-heavy-forwarder/m-p/357320#M43268</guid>
      <dc:creator>rsanders30</dc:creator>
      <dc:date>2017-12-27T15:02:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Tenable: Using add-on without a heavy forwarder</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Using-add-on-without-a-heavy-forwarder/m-p/357321#M43269</link>
      <description>&lt;P&gt;You cant use a UF because the TA leverages the REST API using the Python Framework - This is not part of the Splunk UF, so you will have to install a heavy forwarder (on your nessus server would be fine).&lt;/P&gt;

&lt;P&gt;You can then configure the inputs via the webUI on the HF, or via configuration files as you choose.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2017 15:09:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Using-add-on-without-a-heavy-forwarder/m-p/357321#M43269</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-12-27T15:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Tenable: Using add-on without a heavy forwarder</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Using-add-on-without-a-heavy-forwarder/m-p/357322#M43270</link>
      <description>&lt;P&gt;Thank you. I will have to look at setting up a HF. Just seems inconvenient to do this for this one thing. However, I am hoping the outcome will be worth it. Appreciate your help!&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2017 15:58:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Tenable-Using-add-on-without-a-heavy-forwarder/m-p/357322#M43270</guid>
      <dc:creator>rsanders30</dc:creator>
      <dc:date>2017-12-27T15:58:52Z</dc:date>
    </item>
  </channel>
</rss>

