All Apps and Add-ons

Splunk Add-on for Tenable (seemingly) randomly stops pulling data.

chrishartsock
Path Finder

I am running Splunk Add-on for Tenable 5.1.1 on a heavy forwarder that is running Splunk 6.6.3 to pull vulnerability data from Tenable Security Center. I am having an issue where the add-on stops pulling. This usually happens around once a day. The odd the is I am not getting any errors or even warnings in the logs. It will be working perfectly and then just stops pulling. When it stops I can go in, disable the input, change the checkpoint value to the timestamp of the last event pulled in, then re-enable the input and it will start pulling in again without issue.

I can see in the logs that it is actually still attempting to do something even though it isn't pulling anything. The following is getting logged every 2 minutes (which is the schedule it runs on):

2017-09-11 20:06:57,601 +0000 log_level=INFO, pid=13810, tid=Thread-2, file=scheduler.py, func_name=get_ready_jobs, code_line_no=100 | Get 1 ready jobs, next duration is 119.999509, and there are 1 jobs scheduling
2017-09-11 20:06:57,601 +0000 log_level=INFO, pid=13810, tid=Thread-6, file=thread_pool.py, func_name=_run, code_line_no=261 | Thread work_queue_size=0

Any ideas would be greatly appreciated.

Note: I have been dealing with this for quite a while. Even when the HF was on Splunk 6.5.x.

Yunagi
Communicator

The latest version of the Splunk Add-on for Tenable is 5.1.2. It was released in October 2017.

The Fixed Issues section for 5.1.2 says:

Version 5.1.2 of the Splunk Add-on for Tenable fixes the following issues.

2017-08-22  ADDON-13413     Tenable input stops pulling vulnerability data 

Have you tested 5.1.2?

0 Karma

kcooper
Communicator

The same issue just started with our tenable add-on.
we were receiving data and now it stopped
I restarted the Splunk service on the DCN but still doesn't work
Anyone have any additional recommendations?

0 Karma

ccsfdave
Builder

I was having this issue with 5.1.1, upgraded last week to 5.1..3. Worked for a while, now it is broken again!

0 Karma

kamal_jagga
Contributor

Has anyone tested this ?

0 Karma

chrishartsock
Path Finder

We are now on 5.1.2 and still experiencing the same issue.

benlc
Path Finder

It seems we have a very similiar problem. Also a restart of the HF does solve the problem here.
Thanks for any help.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...