<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to forward events to syslog/nessus security center? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-to-syslog-nessus-security-center/m-p/230976#M44965</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;We want to forward all events to Nessus LCE Server (Nessus Security Center).&lt;/P&gt;
&lt;P&gt;Since we have all Splunk Servers deployed on Windows, we cannot use the Nessus LCE Agent which is only available for some Linux Distros.&lt;/P&gt;
&lt;P&gt;So we've tried to forward the events using the outputs.conf (tried tcpout and syslog).&lt;/P&gt;
&lt;P&gt;Unfortunately the LCE Server is not able to normalize these events since they aren't sent in a proper syslog format.&lt;/P&gt;
&lt;P&gt;One Event is splittet into multiple lines. I'm not sure if it's a splunk or a nessus lce issue.&lt;/P&gt;
&lt;P&gt;Anybody who has a similar setup with splunk and nessus? Any hints?&lt;/P&gt;
&lt;P&gt;Thx &amp;amp; Regards&lt;BR /&gt;Nicolas&lt;/P&gt;</description>
    <pubDate>Sun, 22 May 2022 19:02:09 GMT</pubDate>
    <dc:creator>nicocin</dc:creator>
    <dc:date>2022-05-22T19:02:09Z</dc:date>
    <item>
      <title>How to forward events to syslog/nessus security center?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-to-syslog-nessus-security-center/m-p/230976#M44965</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;We want to forward all events to Nessus LCE Server (Nessus Security Center).&lt;/P&gt;
&lt;P&gt;Since we have all Splunk Servers deployed on Windows, we cannot use the Nessus LCE Agent which is only available for some Linux Distros.&lt;/P&gt;
&lt;P&gt;So we've tried to forward the events using the outputs.conf (tried tcpout and syslog).&lt;/P&gt;
&lt;P&gt;Unfortunately the LCE Server is not able to normalize these events since they aren't sent in a proper syslog format.&lt;/P&gt;
&lt;P&gt;One Event is splittet into multiple lines. I'm not sure if it's a splunk or a nessus lce issue.&lt;/P&gt;
&lt;P&gt;Anybody who has a similar setup with splunk and nessus? Any hints?&lt;/P&gt;
&lt;P&gt;Thx &amp;amp; Regards&lt;BR /&gt;Nicolas&lt;/P&gt;</description>
      <pubDate>Sun, 22 May 2022 19:02:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-to-syslog-nessus-security-center/m-p/230976#M44965</guid>
      <dc:creator>nicocin</dc:creator>
      <dc:date>2022-05-22T19:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: Forward events to syslog/nessus security center</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-to-syslog-nessus-security-center/m-p/230977#M44966</link>
      <description>&lt;P&gt;Hi nicocin,&lt;BR /&gt;
in &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.1/Forwarding/Forwarddatatothird-partysystemsd"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.1/Forwarding/Forwarddatatothird-partysystemsd&lt;/A&gt;&lt;BR /&gt;
you can find all the configuration for your need&lt;BR /&gt;
About the format problem , you could send not raw data but parsed data &lt;CODE&gt;(sendCookedData=True)&lt;/CODE&gt; so you can structure events as you prefer.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2017 13:27:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-to-syslog-nessus-security-center/m-p/230977#M44966</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-01-17T13:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: Forward events to syslog/nessus security center</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-to-syslog-nessus-security-center/m-p/598771#M104428</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi, I realize this is an older question, and I am not sure if this directly answers your question, but perhaps it could be of some help.&lt;BR /&gt;&lt;BR /&gt;I recently developed a free open-source application called TenaPull, which processes Nessus data for ingestion by Splunk.&amp;nbsp; There is more information here:&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/I-developed-an-application-to-process-Nessus-data-for-Splunk/m-p/598592" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Getting-Data-In/I-developed-an-application-to-process-Nessus-data-fo...&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;GitHub repo:&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://github.com/billyJoePiano/TenaPull" target="_blank" rel="nofollow noopener noreferrer"&gt;https://github.com/billyJoePiano/TenaPull&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 21 May 2022 19:19:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-events-to-syslog-nessus-security-center/m-p/598771#M104428</guid>
      <dc:creator>wanderson7</dc:creator>
      <dc:date>2022-05-21T19:19:49Z</dc:date>
    </item>
  </channel>
</rss>

