All Apps and Add-ons

Issues with Qualys Technology Add-on (TA) 1.5.1 unable to fetch data

sayantabasak
Explorer

Hello All,

We are facing issues with our Qualys Technology Add-on (TA) 1.5.1 where it is unable to fetch any data ( host detection/knowledge base ) from Cloud api.

ta_QualysCloudPlatform.log:
TA-QualysCloudPlatform: 2019-09-17 06:16:11 PID=18177 [MainThread] INFO: TA-QualysCloudPlatform (knowledge_base) - Making request: https://certs.qualys.eu/msp/about.php with params={}
TA-QualysCloudPlatform: 2019-09-17 06:21:11 PID=18177 [MainThread] INFO: TA-QualysCloudPlatform (knowledge_base) - Making request: https://certs.qualys.eu/msp/about.php with params={}

splunkd.log:
09-17-2019 06:26:12.124 +0200 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-QualysCloudPlatform/bin/qualys.py" INFO:TA-QualysCloudPlatform (knowledge_base):Making request: https://certs.qualys.eu/msp/about.php with params={}
09-17-2019 06:31:12.156 +0200 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-QualysCloudPlatform/bin/qualys.py" INFO:TA-QualysCloudPlatform (knowledge_base):Making request: https://certs.qualys.eu/msp/about.php with params={}

Configuration:
Qualys TA has been installed in both Search head and heavy forwarder as per the Qualys guidelines
Host_dection input has been enabled in HF and KB input enabled in SH

Configuration on SH:

inputs.conf
[qualys://knowledge_base]
duration = */5 * * * *
index = main
start_date = 1999-01-01T00:00:00Z
disabled = 0

qualys.conf
[setupentity]
api_server = https://certs.qualys.eu
ca_key = /opt/splunk/etc/auth/qualys/client_key.key
ca_path = /opt/splunk/etc/auth/qualys/client_cert.cert
ca_pass = password ( hashed out in passwords.conf )
username = username ( hashed out in passwords.conf )
password = password ( hashed out in passwords.conf )
cs_log_container_summary_events = 0
cs_log_individual_container_events = 0
cs_log_individual_events = 0
cs_log_summary_events = 0
cs_multi_threading_enabled = 0
enable_debug = 1
enable_full_pull = 0
log_detections = 0
log_extra_host_summary = 0
log_host_details_in_detections = 0
log_host_summary = 0
log_individual_compliance_events = 0
log_policy_summary = 0
proxy_server = proxy_server_ip:port
use_ca = 1
use_multi_threading = 0
use_multi_threading_for_was = 0
use_proxy = 1

The api pull works when done via curl command using the same certificate/credentials and proxy from the same server just not happening from qualys add-on.

Any suggestions will be appreciated

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...