All Apps and Add-ons

Tenable Add-On for Splunk ins't loging into Security Center with interval

jscraig2006
Communicator

After installation and configuration of Tenable Add-On, It will only log in once into Security Center. If I restart Splunk or update the configuration, it will also log in once. But running on the scheduled interval, it does not.

OS: RHEL
Splunk 7.2
Tenanble.SC version 5.9.0
Tenable Add-On for Splunk version 2.0.1

looking at the ta_tenable_tenable_securitycenter.log appears to be working, but i do see a connection drop every 10 mins which is the set inverval.

2019-06-19 13:33:38,784 DEBUG pid=11942 tid=MainThread file=connectionpool.py:_make_request:400 | https://securitycenter.cloud.com:443 "POST /rest/analysis HTTP/1.1" 200 None

2019-06-19 13:51:28,339 DEBUG pid=11942 tid=MainThread file=connectionpool.py:_get_conn:247 | Resetting dropped connection: securitycenter.cloud.com

Any assistance is appreciated. Thanks in advance.

0 Karma
1 Solution

nkeuning
Communicator

Please submit a support ticket to us with a copy of your full log so we can help identify what is going on.

View solution in original post

0 Karma

nkeuning
Communicator

Please submit a support ticket to us with a copy of your full log so we can help identify what is going on.

0 Karma

jscraig2006
Communicator

It started working again which is a mystery. If it stops, i'll be sure to open a case.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...