All Apps and Add-ons

Will somebody please fix the Splunk QualysGuard app?

responsys_cm
Builder

I'm usually pretty impressed with the apps built by the Splunk team. That is not the case with the Splunk for QualysGuard app. When the app is installed on 4.3 (Windows or Linux), there are a dozen or so errors like the following:

Error while parsing 'C:\Program Files\Splunk\etc\apps\QualysGuard\default\data\ui\views\PaxHeader\searchvulnkb.xml': syntax error: line 1, column 0

Line 1 in those files is:

The dashboard.html file does not exist anywhere within the Qualys app or the default Splunk build.

I can successfully get Splunk to login to the Qualys KB and download the contents. But when I look at log file generated by the python scripts, all of the CVSS metrics are empty. When I put the URL into a browser, I see all of that data correctly. So, that would seem to indicate that the XML style sheets used by the python script to extract data isn't working properly.

I've emailed both the author of the app and the support address listed in the README and gotten no response...

Tags (1)
0 Karma

TQP9999
New Member

can you help me get the API connector working with Qualys? when I ran the module i get error below

Traceback (most recent call last):
File "C:\Program Files\Splunk\etc\apps\QualysGuard\bin\qualysapi.py", line 13, in
APP_PATH = os.path.join(os.environ ['SPLUNK_HOME'], 'etc', 'apps', 'QualysGuard')
File "C:\Python27\lib\os.py", line 423, in getitem
return self.data[key.upper()]
KeyError: 'SPLUNK_HOME'

0 Karma

DaveSavage
Builder

Post this as your own submission for better visibility? The 'Key Words' will pick it out thereafter?
Br, Dave

0 Karma

responsys_cm
Builder

Thanks! I could probably download the KB with curl and write field extractions for everything, but that seems like a ton of work. I appreciate the quick reply.

Any idea why Splunk is complaining about the view template line?

0 Karma

araitz
Splunk Employee
Splunk Employee

dashboard.html is not in the app, but it is in the view system. Almost all dashboards, regardless of the app, use dashboard.html as the view template.

I do think there is a problem in the app based on your experience and the two other issues reported here on Answers, and I have alerted the folks responsible for it.

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...