All Apps and Add-ons

Not able to generate vulnerability data from a specific account ID

shabaka321
New Member

I have a generated a search query as seen below and I can generate qualys vulnerability data from it, however when I try to append a specific AWS account ID to generate EC2 metadata matching the vulnerability data I get no results.

eventtype=qualys_vm_detection_event | fillnull value=- PROTOCOL DNS | dedup 1 HOST_ID, QID, PROTOCOL, STATUS keepempty=true sortby -_time | search STATUS != "FIXED" | stats list(QID) as QID by OS, DNS, HOST_ID, IP, | lookup qualys_kb_lookup QID OUTPUT TITLE SEVERITY | table OS, DNS, HOST_ID, IP, QID, TITLE, SEVERITY

Is there a way to generate the same data but only from a specific aws account_ID on a table format

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...