<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Add-on for Tenable: Security Center Logs Failed to Index in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Tenable-Security-Center-Logs-Failed-to-Index/m-p/297589#M56320</link>
    <description>&lt;P&gt;I've actually had some luck just re-installing app on an existing Indexer that did not have the app previously. Made no changes to any python files or setup things, just re-added inputs through the App on Splunk and seems to be working about. Still curious about that error, but reapplying app to new indexer has worked for me for now.&lt;/P&gt;</description>
    <pubDate>Mon, 23 Oct 2017 19:36:50 GMT</pubDate>
    <dc:creator>gworkun</dc:creator>
    <dc:date>2017-10-23T19:36:50Z</dc:date>
    <item>
      <title>Splunk Add-on for Tenable: Security Center Logs Failed to Index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Tenable-Security-Center-Logs-Failed-to-Index/m-p/297585#M56316</link>
      <description>&lt;P&gt;On Splunk 6.6, most up-to-date Splunk Add-On for Tenable. Been using it successfully from around February 2017 til middle of May 2017 with no issues, but after a Splunk update or two, have noticed the logs stopped flowing into Splunk. &lt;/P&gt;

&lt;P&gt;No network change, Security Center user change to be noted, but seeing the following error at regular intervals coming in (once every 60-90 seconds, just depends on the interval I have set or changed to troubleshoot). Didn't know if this was due to an update to Splunk that the Add-On did not account for, or if it was something else. Seeing some few other questions with similar reported issues, but wanted to bump the posts up with this error.&lt;/P&gt;

&lt;H2&gt;Any assistance or direction would be fantastic!&lt;/H2&gt;

&lt;P&gt;885 +0000 log_level=ERROR, pid=2248, tid=Thread-6, file=ta_data_collector.py, func_name=index_data, code_line_no=118 | [stanza_name="SecurityCenterInput" data="sc_vulnerability" server="SecurityCenter"] Failed to index data&lt;BR /&gt;
Traceback (most recent call last):&lt;BR /&gt;
  File "C:\Program Files\Splunk\etc\apps\Splunk_TA_nessus\bin\splunk_ta_nessus\splunktaucclib\data_collection\ta_data_collector.py", line 115, in index_data&lt;BR /&gt;
    self.&lt;EM&gt;do_safe_index()&lt;BR /&gt;
  File "C:\Program Files\Splunk\etc\apps\Splunk_TA_nessus\bin\splunk_ta_nessus\splunktaucclib\data_collection\ta_data_collector.py", line 148, in _do_safe_index&lt;BR /&gt;
    self._client = self._create_data_client()&lt;BR /&gt;
  File "C:\Program Files\Splunk\etc\apps\Splunk_TA_nessus\bin\splunk_ta_nessus\splunktaucclib\data_collection\ta_data_collector.py", line 89, in _create_data_client&lt;BR /&gt;
    ckpt = self._get_ckpt()&lt;BR /&gt;
  File "C:\Program Files\Splunk\etc\apps\Splunk_TA_nessus\bin\splunk_ta_nessus\splunktaucclib\data_collection\ta_data_collector.py", line 80, in _get_ckpt&lt;BR /&gt;
    return self._checkpoint_manager.get_ckpt()&lt;BR /&gt;
  File "C:\Program Files\Splunk\etc\apps\Splunk_TA_nessus\bin\splunk_ta_nessus\splunktaucclib\data_collection\ta_checkpoint_manager.py", line 31, in get_ckpt&lt;BR /&gt;
    return self._store.get_state(key)&lt;BR /&gt;
  File "C:\Program Files\Splunk\etc\apps\Splunk_TA_nessus\bin\splunk_ta_nessus\splunktalib\state_store.py", line 141, in get_state&lt;BR /&gt;
    state = json.load(jsonfile)&lt;BR /&gt;
  File "C:\Program Files\Splunk\Python-2.7\Lib\json__init&lt;/EM&gt;&lt;EM&gt;.py", line 291, in load&lt;BR /&gt;
    **kw)&lt;BR /&gt;
  File "C:\Program Files\Splunk\Python-2.7\Lib\json__init&lt;/EM&gt;_.py", line 339, in loads&lt;BR /&gt;
    return _default_decoder.decode(s)&lt;BR /&gt;
  File "C:\Program Files\Splunk\Python-2.7\Lib\json\decoder.py", line 364, in decode&lt;BR /&gt;
    obj, end = self.raw_decode(s, idx=_w(s, 0).end())&lt;BR /&gt;
  File "C:\Program Files\Splunk\Python-2.7\Lib\json\decoder.py", line 382, in raw_decode&lt;BR /&gt;
    raise ValueError("No JSON object could be decoded")&lt;/P&gt;

&lt;H2&gt;ValueError: No JSON object could be decoded&lt;/H2&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:10:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Tenable-Security-Center-Logs-Failed-to-Index/m-p/297585#M56316</guid>
      <dc:creator>gworkun</dc:creator>
      <dc:date>2020-09-29T16:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Tenable: Security Center Logs Failed to Index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Tenable-Security-Center-Logs-Failed-to-Index/m-p/297586#M56317</link>
      <description>&lt;P&gt;Despite searching, I only found your question &lt;EM&gt;after&lt;/EM&gt; posting mine!&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/583400/splunk-ta-nessus-stalls-collecting-from-security-c.html?minQuestionBodyLength=80#question-583400"&gt;https://answers.splunk.com/answers/583400/splunk-ta-nessus-stalls-collecting-from-security-c.html?minQuestionBodyLength=80#question-583400&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Smells like it could be related - will see if I can see the same error in mine.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 08:13:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Tenable-Security-Center-Logs-Failed-to-Index/m-p/297586#M56317</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-10-16T08:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Tenable: Security Center Logs Failed to Index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Tenable-Security-Center-Logs-Failed-to-Index/m-p/297587#M56318</link>
      <description>&lt;P&gt;Indeed, tried your temporary solution of disabling/enabling the input to no avail. I'll keep exploring other routes, but seems like may need some guidance from app creators or those that have seen this problem often.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 13:32:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Tenable-Security-Center-Logs-Failed-to-Index/m-p/297587#M56318</guid>
      <dc:creator>gworkun</dc:creator>
      <dc:date>2017-10-16T13:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Tenable: Security Center Logs Failed to Index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Tenable-Security-Center-Logs-Failed-to-Index/m-p/297588#M56319</link>
      <description>&lt;P&gt;Any luck?  Im having this problem with v5.1.1 on Splunk 6.5.2.  Upgraded app to v5.1.2 and still no luck. &lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2017 19:29:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Tenable-Security-Center-Logs-Failed-to-Index/m-p/297588#M56319</guid>
      <dc:creator>rosslopez</dc:creator>
      <dc:date>2017-10-23T19:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Tenable: Security Center Logs Failed to Index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Tenable-Security-Center-Logs-Failed-to-Index/m-p/297589#M56320</link>
      <description>&lt;P&gt;I've actually had some luck just re-installing app on an existing Indexer that did not have the app previously. Made no changes to any python files or setup things, just re-added inputs through the App on Splunk and seems to be working about. Still curious about that error, but reapplying app to new indexer has worked for me for now.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2017 19:36:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Tenable-Security-Center-Logs-Failed-to-Index/m-p/297589#M56320</guid>
      <dc:creator>gworkun</dc:creator>
      <dc:date>2017-10-23T19:36:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Tenable: Security Center Logs Failed to Index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Tenable-Security-Center-Logs-Failed-to-Index/m-p/297590#M56321</link>
      <description>&lt;P&gt;Funnily enough, I was going to close my question today with an update saying "all has been well since the update", however - it seems that my HF got restarted at the weekend, so its not really had time to prove itself yet.&lt;/P&gt;

&lt;P&gt;Stay tuned...&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2017 19:39:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Tenable-Security-Center-Logs-Failed-to-Index/m-p/297590#M56321</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-10-23T19:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Tenable: Security Center Logs Failed to Index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Tenable-Security-Center-Logs-Failed-to-Index/m-p/598772#M104429</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi, I realize this is an older question, and I am not sure if this directly answers your question, but perhaps it could be of some help.&lt;BR /&gt;&lt;BR /&gt;I recently developed a free open-source application called TenaPull, which processes Nessus data for ingestion by Splunk.&amp;nbsp; There is more information here:&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/I-developed-an-application-to-process-Nessus-data-for-Splunk/m-p/598592" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Getting-Data-In/I-developed-an-application-to-process-Nessus-data-fo...&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;GitHub repo:&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://github.com/billyJoePiano/TenaPull" target="_blank" rel="nofollow noopener noreferrer"&gt;https://github.com/billyJoePiano/TenaPull&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 21 May 2022 19:20:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Tenable-Security-Center-Logs-Failed-to-Index/m-p/598772#M104429</guid>
      <dc:creator>wanderson7</dc:creator>
      <dc:date>2022-05-21T19:20:23Z</dc:date>
    </item>
  </channel>
</rss>

