All Apps and Add-ons

Vulnerabilities number in splunk not matching vulnerabilities in Tenable for same ip(Machine)

AFerns08
Engager

Hi,
we just ran a scan on a network and found some vulnerabilities in tenable for one particular machine(ipv4).

lets say 10 vulnerabilities were discovered on the tenable app but when i was checking splunk, i could only see 8 vulnerabilities in splunk. 2 events(vulnerabilities) were missing in splunk for the same machine.

We have the Tenable App for Splunk installed on our splunk search head.
Is this a truncation issue? below are the config from transforms.conf
[tenable:nnm:vuln]
DATETIME_CONFIG = CURRENT
EVAL-vendor_product = "Tenable xxx"
EVAL-product = "xxx"
EVAL-vendor = "Tenable"
TRUNCATE = 68000000
SHOULD_LINEMERGE = 0

0 Karma

nkeuning
Communicator

Please open a case with support.tenable.com and we can help track this down.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...