All Apps and Add-ons

Issues with Qualys Technology Add-on (TA) 1.5.1 unable to fetch data

sayantabasak
Explorer

Hello All,

We are facing issues with our Qualys Technology Add-on (TA) 1.5.1 where it is unable to fetch any data ( host detection/knowledge base ) from Cloud api.

ta_QualysCloudPlatform.log:
TA-QualysCloudPlatform: 2019-09-17 06:16:11 PID=18177 [MainThread] INFO: TA-QualysCloudPlatform (knowledge_base) - Making request: https://certs.qualys.eu/msp/about.php with params={}
TA-QualysCloudPlatform: 2019-09-17 06:21:11 PID=18177 [MainThread] INFO: TA-QualysCloudPlatform (knowledge_base) - Making request: https://certs.qualys.eu/msp/about.php with params={}

splunkd.log:
09-17-2019 06:26:12.124 +0200 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-QualysCloudPlatform/bin/qualys.py" INFO:TA-QualysCloudPlatform (knowledge_base):Making request: https://certs.qualys.eu/msp/about.php with params={}
09-17-2019 06:31:12.156 +0200 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-QualysCloudPlatform/bin/qualys.py" INFO:TA-QualysCloudPlatform (knowledge_base):Making request: https://certs.qualys.eu/msp/about.php with params={}

Configuration:
Qualys TA has been installed in both Search head and heavy forwarder as per the Qualys guidelines
Host_dection input has been enabled in HF and KB input enabled in SH

Configuration on SH:

inputs.conf
[qualys://knowledge_base]
duration = */5 * * * *
index = main
start_date = 1999-01-01T00:00:00Z
disabled = 0

qualys.conf
[setupentity]
api_server = https://certs.qualys.eu
ca_key = /opt/splunk/etc/auth/qualys/client_key.key
ca_path = /opt/splunk/etc/auth/qualys/client_cert.cert
ca_pass = password ( hashed out in passwords.conf )
username = username ( hashed out in passwords.conf )
password = password ( hashed out in passwords.conf )
cs_log_container_summary_events = 0
cs_log_individual_container_events = 0
cs_log_individual_events = 0
cs_log_summary_events = 0
cs_multi_threading_enabled = 0
enable_debug = 1
enable_full_pull = 0
log_detections = 0
log_extra_host_summary = 0
log_host_details_in_detections = 0
log_host_summary = 0
log_individual_compliance_events = 0
log_policy_summary = 0
proxy_server = proxy_server_ip:port
use_ca = 1
use_multi_threading = 0
use_multi_threading_for_was = 0
use_proxy = 1

The api pull works when done via curl command using the same certificate/credentials and proxy from the same server just not happening from qualys add-on.

Any suggestions will be appreciated

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...