All Apps and Add-ons

How to get Qualys knowledgebase data into splunk index after qualys_kb.csv lookup getting updated?

sujanay02
New Member

Hi All,

I am integrating Qualys with splunk to get the VM data.I installed Qualys add on on HF and SH, and enabled host_detection input on HF nad knowledge_base input on SH.I am successfully getting host_detection data into main index .When script runs for knowledgebase data,first it is adding to tmp directory in ADD-ON folder and updating lookup table qualys_kb.csv but not into main index.Can you let me know where i am missing?i couldnot see any errors on /opt/splunk/var/log/splunk/ta_qualyscloudplatform.log and splunkd.log.
INput on HF
[qualys://host_detection]
duration = */10 * * * *(for every 10 min for testing )
index = vulnerability
start_date = 2109-09-01T00:00:00Z
disabled = 0
Input on SH
[qualys://knowledge_base]
duration = */15 * * * *(for every 15 min for testing)
index = vulnerability
start_date = 2019-09-01T00:00:00Z
disabled = 0

Can you help me out ?

0 Karma
Get Updates on the Splunk Community!

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...

Stay Connected: Your Guide to October Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...