<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rapid7intsightsvm in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-changes-we-need-to-get-the-data-into-test-index/m-p/634632#M108590</link>
    <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;Question is a little broad without knowing what you've done already. To resolve, will require a bit more info:&lt;BR /&gt;&lt;BR /&gt;1. Is this a standalone instance or a forwarder in a distributed deployment? (if it's a forwarder, are any other inputs whos data is successfully being forwarded to the index layer and indexed? (to eliminate firewall or traffic blocking at the receiving node or along the path))&lt;BR /&gt;2. Does the index "test" exist and is it enabled? (search: | rest /services/data/indexes | search title=test | table title, disabled or Settings &amp;gt; Indexes &amp;gt; filter for test)&lt;BR /&gt;3. Have you checked the _internal logs for any errors with the mod input&lt;BR /&gt;4. Have you confirmed the input key is correct and able to authenticate to the API (try deleting and recreating the input in the TA)&lt;/P&gt;</description>
    <pubDate>Wed, 15 Mar 2023 18:39:22 GMT</pubDate>
    <dc:creator>John_Littleton</dc:creator>
    <dc:date>2023-03-15T18:39:22Z</dc:date>
    <item>
      <title>What changes we need to get the data into test index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-changes-we-need-to-get-the-data-into-test-index/m-p/634604#M108588</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;While trying to configure the rapid7intsightsvm app the data is not indexing to index which&amp;nbsp; I have configured.&lt;/P&gt;
&lt;P&gt;Name&lt;BR /&gt;InsightVM_Assets&lt;BR /&gt;Interval&lt;BR /&gt;3600&lt;BR /&gt;Full import schedule (Days)&lt;BR /&gt;0&lt;BR /&gt;Index&lt;BR /&gt;test&lt;BR /&gt;Status&lt;BR /&gt;false&lt;BR /&gt;InsightVM Connection&lt;BR /&gt;Splunk_Rapid7&lt;BR /&gt;Asset Filter&lt;BR /&gt;Site IN [Rapid7]&lt;BR /&gt;Import vulnerabilities&lt;BR /&gt;1&lt;BR /&gt;Include same vulnerabilities&lt;BR /&gt;0&lt;BR /&gt;what changes we need to get the data in to&amp;nbsp; test index ??&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 18:40:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-changes-we-need-to-get-the-data-into-test-index/m-p/634604#M108588</guid>
      <dc:creator>smith_</dc:creator>
      <dc:date>2023-03-15T18:40:26Z</dc:date>
    </item>
    <item>
      <title>Re: Rapid7intsightsvm</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-changes-we-need-to-get-the-data-into-test-index/m-p/634632#M108590</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;Question is a little broad without knowing what you've done already. To resolve, will require a bit more info:&lt;BR /&gt;&lt;BR /&gt;1. Is this a standalone instance or a forwarder in a distributed deployment? (if it's a forwarder, are any other inputs whos data is successfully being forwarded to the index layer and indexed? (to eliminate firewall or traffic blocking at the receiving node or along the path))&lt;BR /&gt;2. Does the index "test" exist and is it enabled? (search: | rest /services/data/indexes | search title=test | table title, disabled or Settings &amp;gt; Indexes &amp;gt; filter for test)&lt;BR /&gt;3. Have you checked the _internal logs for any errors with the mod input&lt;BR /&gt;4. Have you confirmed the input key is correct and able to authenticate to the API (try deleting and recreating the input in the TA)&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 18:39:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-changes-we-need-to-get-the-data-into-test-index/m-p/634632#M108590</guid>
      <dc:creator>John_Littleton</dc:creator>
      <dc:date>2023-03-15T18:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: Rapid7intsightsvm</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-changes-we-need-to-get-the-data-into-test-index/m-p/634718#M108615</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/245401"&gt;@John_Littleton&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;1. yes it is standalone instance&lt;/P&gt;&lt;P&gt;2. yes the test index is configured and enabled&lt;/P&gt;&lt;P&gt;3. Yes I have checked the internal logs&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;INFO pid=24473 tid=MainThread file=base_modinput.py:log_info:295 | Last import time InsightVM_Assets-last_import_time for InsightVM_Assets has not been updated and remains at None&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;4. Yes the input key is correct and able to authenticate to the API&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 08:30:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-changes-we-need-to-get-the-data-into-test-index/m-p/634718#M108615</guid>
      <dc:creator>smith_</dc:creator>
      <dc:date>2023-03-16T08:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: Rapid7intsightsvm</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-changes-we-need-to-get-the-data-into-test-index/m-p/634812#M108628</link>
      <description>&lt;P&gt;It looks like the input script isn't running:&lt;/P&gt;&lt;P&gt;If it hasn't worked at all, I would start from scratch. In the TA, I would delete the connection and the input and recreate them with a new API key.&lt;BR /&gt;&lt;BR /&gt;Regenerate a new API key:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;A href="https://insight.rapid7.com/login" target="_blank" rel="noopener"&gt;Sign in&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to the Insight Platform.&lt;/LI&gt;&lt;LI&gt;Select the gear icon in the top menu and click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;API Keys&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Organization Key&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;+ New Key&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Enter a name for the key and click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Generate&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Copy and store the generated key in a secure location.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Recreate the connection&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Navigate to the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Rapid7 InsightVM Technology Add-On&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;available under the Apps menu in Splunk.&lt;/LI&gt;&lt;LI&gt;Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Configuration&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Add&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Enter a name for the connection.&lt;/LI&gt;&lt;LI&gt;Enter your region, which is a two-character string based on your location (such as&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;us&lt;/SPAN&gt;&lt;/SPAN&gt;).&lt;UL&gt;&lt;LI&gt;Additional region information is available in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.rapid7.com/insight/product-apis#supported-regions" target="_blank" rel="noopener"&gt;Supported Regions&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;section of the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.rapid7.com/insight/product-apis" target="_blank" rel="noopener"&gt;Product APIs&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;page.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Enter your generated API key.&lt;/LI&gt;&lt;LI&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Add.&lt;/STRONG&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Recreate the input:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Inputs &amp;gt; Create New Input&lt;BR /&gt;&lt;/STRONG&gt;all per the doc&amp;nbsp;&lt;A href="https://docs.rapid7.com/insightvm/insightvm-technology-add-on-for-splunk/" target="_blank" rel="noopener"&gt;https://docs.rapid7.com/insightvm/insightvm-technology-add-on-for-splunk/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Also, if you are using an older Splunk install, check /opt/splunk/bin/ and see what python you have. I believe the input in the TA uses python3 by default.&lt;BR /&gt;&lt;BR /&gt;Also, may try:&lt;BR /&gt;A different index (i.e. test2)&lt;BR /&gt;&lt;SPAN&gt;Restarting splunkd&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If you're still not getting data in, the issue is likely not with Splunk. The TA is vendor built and supported, so I would reach out to Rapid7 and see if they can t/s the connection.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 19:28:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-changes-we-need-to-get-the-data-into-test-index/m-p/634812#M108628</guid>
      <dc:creator>John_Littleton</dc:creator>
      <dc:date>2023-03-16T19:28:03Z</dc:date>
    </item>
  </channel>
</rss>

