Hi everyone,
I have two problems.
First one, SSL CERT. VERIFY FAILED:
2018-03-19 05:49:04,496 +0000 log_level=ERROR, pid=32002, tid=Thread-6, file=ta_tenable_sc_data_collector.py, func_name=_do_job_one_time, code_line_no=61 | [stanza_name="deneme_input2" data="sc_vulnerability" server="Deneme_SERVER"] [SSL: CERTIFICATE_VERIFY_FAILED] certificate verification failed. The certificate validation is enabled. You may need to check the certificate and refer to the documentation and add it to the trust list.
I followed these steps but not working for me 😞 >> https://docs.splunk.com/Documentation/AddOns/released/Nessus/Troubleshoot
Second one, Failed To Index Data:
2018-03-19 05:50:38,496 +0000 log_level=ERROR, pid=32002, tid=Thread-5, file=ta_data_collector.py, func_name=index_data, code_line_no=118 | [stanza_name="deneme_input2" data="sc_vulnerability" server="Deneme_SERVER"] Failed to index data
Traceback (most recent call last):
File "/opt/splunk/etc/apps/Splunk_TA_nessus/bin/splunk_ta_nessus/splunktaucclib/data_collection/ta_data_collector.py", line 115, in index_data
self._do_safe_index()
File "/opt/splunk/etc/apps/Splunk_TA_nessus/bin/splunk_ta_nessus/splunktaucclib/data_collection/ta_data_collector.py", line 148, in _do_safe_index
self._client = self._create_data_client()
File "/opt/splunk/etc/apps/Splunk_TA_nessus/bin/splunk_ta_nessus/splunktaucclib/data_collection/ta_data_collector.py", line 95, in _create_data_client
self._checkpoint_manager)
File "/opt/splunk/etc/apps/Splunk_TA_nessus/bin/splunk_ta_nessus/splunktaucclib/data_collection/ta_data_client.py", line 55, in __init__
self._ckpt)
File "/opt/splunk/etc/apps/Splunk_TA_nessus/bin/splunk_ta_nessus/ta_tenable_sc_data_collector.py", line 18, in do_job_one_time
return _do_job_one_time(all_conf_contents, task_config, ckpt)
File "/opt/splunk/etc/apps/Splunk_TA_nessus/bin/splunk_ta_nessus/ta_tenable_sc_data_collector.py", line 62, in _do_job_one_time
raise Exception
Exception
Collapse
Honestly, I do not know what should I do for this problem 😞
I solved problem with theese steps: https://answers.splunk.com/answers/584167/-splunk-add-on-for-tenable-how-can-i-resolve-basic.html
I solved problem with theese steps: https://answers.splunk.com/answers/584167/-splunk-add-on-for-tenable-how-can-i-resolve-basic.html
One possible reason is that you didn't change your default permissions in Nessus. Change your permissions from Not access to Can view.
For SSL:
Is it working proper if we disable SSL??
local/nessus.conf
[tenable_sc_settings]
disable_ssl_certificate_validation = 0
thanks for your answer @p_gurav. But Which permissions ? if account that ı used to access from splunk to SecurityCenter, this account have security manager role. So, have permissions.
And local/nessus.conf path on SecurityCenter Server? or on Splunk Server ?
local/nessus.conf path on Splunk Server
thanks for your answers @p_gurav. I solved problem with theese steps: https://answers.splunk.com/answers/584167/-splunk-add-on-for-tenable-how-can-i-resolve-basic.html
Please mark the question as answered, perhaps with the answer you found 🙂
Happy to help!!!