All Apps and Add-ons

How do I ingest Nessus Compliance scan results

mmcfarren
New Member

Splunk will ingest the scan reports but it only reports the plugin data not that actual compliance scans. The compliance scans can be exported in .nessus .html .csv formats but the App does not appear to recognize this. is this a limitation of the Nessus API?

using Nessus Pro 6.8.1

0 Karma

kent_farries
Path Finder

We had that issue as well for the .nessus files and our Splunk consultant figured out how to make it work back in 2015. We have since moved away from the .nessus files and instead just use the API which is working well and no longer requires manual intervention. We are using this with Splulnk 6.4.2 and the Splunk Add-on for Nessus 4.0.0. We plan on upgrading to 5.0.0 soon.

We configured the Nessus Add-on with two inputs. Maybe you need to configure the nessus_scan in addition to nessus_plugin.

  • nessus_plugin
  • nessus_scan

We generated the two keys through the Nessus Pro GUI. We used the same keys for both inputs.
Settings, Account, click on the user, selected API Keys and then Generate.

  • Access Key
  • Secret Key

I hope this helps.

Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...