All Apps and Add-ons

Can I use Nessus add-on in Splunk?

maria920
New Member

My organization is using Nessus Cloud and Splunk Enterprise. Recently, I installed Nessus add-on in Splunk, but I don't know how to configure it. There is no instruction available online. The only one documentation I found doesn't work for me. So can you help me? I am wondering if Nessus Cloud is capable with Splunk. Thanks!

Tags (1)
0 Karma

chli_splunk
Splunk Employee
Splunk Employee

Maria, you need to go to https://{Your Nessus Server}/#/user-profile -> API Keys, and click "Generate". Note that the previous tokens will be expired if you re-generate tokens.

alt text

maria920
New Member

so which means the secret key and the access key are the same? Thanks!

0 Karma

maria920
New Member

so which means the secret key and the access key are the same? Thanks!

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Have you looked at the Installation instructions in the documentation? If those instructions are not working for you, please provide specific information about where you got stuck, what you tried, and what went wrong.

0 Karma

maria920
New Member

I have looked this documentation. But it isn't very helpful. So after I installed this add-on , I am trying to configure it. So when I click " manage app"->"set up", I don't enable proxy. Then I just click" save" and nothing happens.
Then I try to click " settings"- > " data input"-> "Splunk Add-on Nessus", it asks me to put access key and secret key, but I don't know what they are.

0 Karma

rpille_splunk
Splunk Employee
Splunk Employee

Maria, are you a Nessus admin in your org? If so, you can generate API keys on your user profile. If not, ask an admin to configure this portion.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...