All Apps and Add-ons

How to get Qualys knowledgebase data into splunk index after qualys_kb.csv lookup getting updated?

sujanay02
New Member

Hi All,

I am integrating Qualys with splunk to get the VM data.I installed Qualys add on on HF and SH, and enabled host_detection input on HF nad knowledge_base input on SH.I am successfully getting host_detection data into main index .When script runs for knowledgebase data,first it is adding to tmp directory in ADD-ON folder and updating lookup table qualys_kb.csv but not into main index.Can you let me know where i am missing?i couldnot see any errors on /opt/splunk/var/log/splunk/ta_qualyscloudplatform.log and splunkd.log.
INput on HF
[qualys://host_detection]
duration = */10 * * * *(for every 10 min for testing )
index = vulnerability
start_date = 2109-09-01T00:00:00Z
disabled = 0
Input on SH
[qualys://knowledge_base]
duration = */15 * * * *(for every 15 min for testing)
index = vulnerability
start_date = 2019-09-01T00:00:00Z
disabled = 0

Can you help me out ?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...