All Apps and Add-ons

Tenable add-on stops after token delete

a_naoum
Path Finder

I have notice that from time to time the add-on stops collecting events for no visible reason (at least from the logs)
So I enable the debug mode in the logs to see if there is some more valuable information. I notice that since 1am we don't have any events, logs are empty as well.

Last recorded message in the tenable logs (ta_tenable_tenable_securitycenter.log) is:

DEBUG pid=30151 tid=MainThread file=connectionpool.py:_make_request:400 | https://xx.xxx.xx.xxx:443 "DELETE /rest/token HTTP/1.1" 200 100

Any idea for the reason?

0 Karma

nkeuning
Communicator

Every time we login we create a session. This call happens every time we are done with the api to delete our session.

0 Karma

nkeuning
Communicator

It is hard to say without much more detail. Can you please open a case with support.tenable.com and include the following:

  • Latest full log from the add-on
  • Splunk Version
  • Tenable Add-on Version
  • Splunk OS
  • Is the add-on running from a Heavy forwarder?
  • Tenable.sc version
  • List item

Please reference this conversation when open the ticket so they can route it accordingly

P.S.
Given the way the add-on pulls/stores data there is a good chance there were not updates for us to pull for many days even if you scanned something.

0 Karma

a_naoum
Path Finder

ok, sound logical but why is not create a new session rather stay dead until I do debug/refresh? It is the second day without events.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...