All Apps and Add-ons

Qualys VM App for Splunk Enterprise: Why are the dashboards searching on event types that are not defined anywhere in the app?

responsys_cm
Builder

I installed the latest release of the Qualys App (the one officially supported by Qualys) and the TA for it.

It would seem that all of the dashboards are driven off of event types that aren't defined anywhere in the app.

The IP lookup dashboard wants to search on eventtype=qualys_vm_detection_event.

The main dashboard and the Hosts dashboard want to search on eventtype=qualys_host_summary_event.

The Qualys Vulnerability Scan searches on source=qualys, but the app uses the path to the script name for pulling in scan results.

This app is completely broken. Does anyone know what the right event types are for this app?

0 Karma

jleggett
Explorer

it is not broken, it works perfectly fine. The event types are all defined in the TA, not the VM App. Please make sure you are using this TA:

https://splunkbase.splunk.com/app/2964/

Did you set up the TA according to the instructions? Are you seeing events from the TA loaded? (sourcetype=qualys:hostdetection)?

Did you previously have the older APp installed (the 1.2.2)? If so, you needed to completely remove that from your Splunk search head first for the new to work properly.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...