<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does the Splunk Add-on for Tenable stops ingesting data randomly? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-Add-on-for-Tenable-stops-ingesting-data/m-p/375835#M45588</link>
    <description>&lt;P&gt;This is not the same issue being reported in all the other threads. &lt;BR /&gt;
In my case, (and a few people have yelled 'me too') the issue is that collection stops with no apparent error:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/583400/splunk-add-on-for-tenable-stalls-when-collecting-f.html"&gt;https://answers.splunk.com/answers/583400/splunk-add-on-for-tenable-stalls-when-collecting-f.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Your example seems quite different, in that you are seeing an issue with authentication:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sc.login(username, password)
       File "/opt/splunk/etc/apps/Splunk_TA_nessus/bin/splunk_ta_nessus/security_center.py", line 46, in login
     self._token = str(result['token'])
     KeyError: 'token'
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I don't know what could cause this, but on the face of it your deployment is working correctly - check the SC logs to see if there were any issues with the credentials you were using at that time. - It also explains why in your env it could start working again, once the auth problem has cleared up.&lt;/P&gt;</description>
    <pubDate>Fri, 16 Feb 2018 12:30:02 GMT</pubDate>
    <dc:creator>nickhills</dc:creator>
    <dc:date>2018-02-16T12:30:02Z</dc:date>
    <item>
      <title>Why does the Splunk Add-on for Tenable stops ingesting data randomly?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-Add-on-for-Tenable-stops-ingesting-data/m-p/375833#M45586</link>
      <description>&lt;P&gt;I've searched through the answers and most suggestions are: to disable and then enable the input, change the Start Time, some have even re-installed the app.  For a while, I only had to open the input in the GUI which resets it, and that would work to get the data coming in again.  Yesterday when, I restarted Splunk for another reason, data started to come again.  I've tried everything but reinstalling the add-on this morning with no luck.  I am running 5.1.2 for the add-on and my Splunk version is 7.0.1.&lt;/P&gt;

&lt;P&gt;Here is the error I'm getting, I have double checked the user name and password both of which have not been changed on Nessus/Security Center and in the Splunk configuration.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2018-02-15 14:01:33,278 +0000 log_level=ERROR, pid=338, tid=Thread-4, file=ta_data_collector.py, func_name=index_data, code_line_no=118 | [stanza_name="Vulnerability" data="sc_vulnerability" server="SecuirtyCenter"] Failed to index data
Traceback (most recent call last):
  File "/opt/splunk/etc/apps/Splunk_TA_nessus/bin/splunk_ta_nessus/splunktaucclib/data_collection/ta_data_collector.py", line 115, in index_data
self._do_safe_index()
  File "/opt/splunk/etc/apps/Splunk_TA_nessus/bin/splunk_ta_nessus/splunktaucclib/data_collection/ta_data_collector.py", line 148, in _do_safe_index
self._client = self._create_data_client()
  File "/opt/splunk/etc/apps/Splunk_TA_nessus/bin/splunk_ta_nessus/splunktaucclib/data_collection/ta_data_collector.py", line 95, in _create_data_client
self._checkpoint_manager)
  File "/opt/splunk/etc/apps/Splunk_TA_nessus/bin/splunk_ta_nessus/splunktaucclib/data_collection/ta_data_client.py", line 55, in __init__
self._ckpt)
  File "/opt/splunk/etc/apps/Splunk_TA_nessus/bin/splunk_ta_nessus/ta_tenable_sc_data_collector.py", line 18, in do_job_one_time
return _do_job_one_time(all_conf_contents, task_config, ckpt)
  File "/opt/splunk/etc/apps/Splunk_TA_nessus/bin/splunk_ta_nessus/ta_tenable_sc_data_collector.py", line 53, in _do_job_one_time
logger_prefix=logger_prefix)
  File "/opt/splunk/etc/apps/Splunk_TA_nessus/bin/splunk_ta_nessus/security_center.py", line 219, in get_security_center
sc.login(username, password)
  File "/opt/splunk/etc/apps/Splunk_TA_nessus/bin/splunk_ta_nessus/security_center.py", line 46, in login
self._token = str(result['token'])
KeyError: 'token'
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 15 Feb 2018 14:13:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-Add-on-for-Tenable-stops-ingesting-data/m-p/375833#M45586</guid>
      <dc:creator>jclehmuth</dc:creator>
      <dc:date>2018-02-15T14:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the Splunk Add-on for Tenable stops ingesting data randomly?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-Add-on-for-Tenable-stops-ingesting-data/m-p/375834#M45587</link>
      <description>&lt;P&gt;This add-on is really frustrating...&lt;BR /&gt;
I came in this morning and it is working again. The majority of our scans run at night, so my usual setting to check for data is about every six hours, I went to adjust the check for data setting then I went to monitor the sourcetype for updates. The last logs came in at 0100, I have no idea what is going on with this add-on.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2018 11:49:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-Add-on-for-Tenable-stops-ingesting-data/m-p/375834#M45587</guid>
      <dc:creator>jclehmuth</dc:creator>
      <dc:date>2018-02-16T11:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the Splunk Add-on for Tenable stops ingesting data randomly?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-Add-on-for-Tenable-stops-ingesting-data/m-p/375835#M45588</link>
      <description>&lt;P&gt;This is not the same issue being reported in all the other threads. &lt;BR /&gt;
In my case, (and a few people have yelled 'me too') the issue is that collection stops with no apparent error:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/583400/splunk-add-on-for-tenable-stalls-when-collecting-f.html"&gt;https://answers.splunk.com/answers/583400/splunk-add-on-for-tenable-stalls-when-collecting-f.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Your example seems quite different, in that you are seeing an issue with authentication:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sc.login(username, password)
       File "/opt/splunk/etc/apps/Splunk_TA_nessus/bin/splunk_ta_nessus/security_center.py", line 46, in login
     self._token = str(result['token'])
     KeyError: 'token'
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I don't know what could cause this, but on the face of it your deployment is working correctly - check the SC logs to see if there were any issues with the credentials you were using at that time. - It also explains why in your env it could start working again, once the auth problem has cleared up.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2018 12:30:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-Add-on-for-Tenable-stops-ingesting-data/m-p/375835#M45588</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-02-16T12:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the Splunk Add-on for Tenable stops ingesting data randomly?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-Add-on-for-Tenable-stops-ingesting-data/m-p/375836#M45589</link>
      <description>&lt;P&gt;I haven't had the issue in a while however, if it is an authentication issue we have an idea of what the problem may be.  Our security center drops connection to AD on occasion, we have a ticket open with Tenable to help resolve the issue.&lt;BR /&gt;
Thanks for pointing that out.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 14:06:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-does-the-Splunk-Add-on-for-Tenable-stops-ingesting-data/m-p/375836#M45589</guid>
      <dc:creator>jclehmuth</dc:creator>
      <dc:date>2018-03-16T14:06:35Z</dc:date>
    </item>
  </channel>
</rss>

