All Apps and Add-ons

How to get Qualys knowledgebase data into splunk index after qualys_kb.csv lookup getting updated?

sujanay02
New Member

Hi All,

I am integrating Qualys with splunk to get the VM data.I installed Qualys add on on HF and SH, and enabled host_detection input on HF nad knowledge_base input on SH.I am successfully getting host_detection data into main index .When script runs for knowledgebase data,first it is adding to tmp directory in ADD-ON folder and updating lookup table qualys_kb.csv but not into main index.Can you let me know where i am missing?i couldnot see any errors on /opt/splunk/var/log/splunk/ta_qualyscloudplatform.log and splunkd.log.
INput on HF
[qualys://host_detection]
duration = */10 * * * *(for every 10 min for testing )
index = vulnerability
start_date = 2109-09-01T00:00:00Z
disabled = 0
Input on SH
[qualys://knowledge_base]
duration = */15 * * * *(for every 15 min for testing)
index = vulnerability
start_date = 2019-09-01T00:00:00Z
disabled = 0

Can you help me out ?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Maximizing the Value of Splunk ES 8.x

Splunk Enterprise Security (ES) continues to be a leader in the Gartner Magic Quadrant, reflecting its pivotal ...