All Apps and Add-ons

Vulnerabilities number in splunk not matching vulnerabilities in Tenable for same ip(Machine)

AFerns08
Engager

Hi,
we just ran a scan on a network and found some vulnerabilities in tenable for one particular machine(ipv4).

lets say 10 vulnerabilities were discovered on the tenable app but when i was checking splunk, i could only see 8 vulnerabilities in splunk. 2 events(vulnerabilities) were missing in splunk for the same machine.

We have the Tenable App for Splunk installed on our splunk search head.
Is this a truncation issue? below are the config from transforms.conf
[tenable:nnm:vuln]
DATETIME_CONFIG = CURRENT
EVAL-vendor_product = "Tenable xxx"
EVAL-product = "xxx"
EVAL-vendor = "Tenable"
TRUNCATE = 68000000
SHOULD_LINEMERGE = 0

0 Karma

nkeuning
Communicator

Please open a case with support.tenable.com and we can help track this down.

0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...