All Apps and Add-ons

Will somebody please fix the Splunk QualysGuard app?


I'm usually pretty impressed with the apps built by the Splunk team. That is not the case with the Splunk for QualysGuard app. When the app is installed on 4.3 (Windows or Linux), there are a dozen or so errors like the following:

Error while parsing 'C:\Program Files\Splunk\etc\apps\QualysGuard\default\data\ui\views\PaxHeader\searchvulnkb.xml': syntax error: line 1, column 0

Line 1 in those files is:

The dashboard.html file does not exist anywhere within the Qualys app or the default Splunk build.

I can successfully get Splunk to login to the Qualys KB and download the contents. But when I look at log file generated by the python scripts, all of the CVSS metrics are empty. When I put the URL into a browser, I see all of that data correctly. So, that would seem to indicate that the XML style sheets used by the python script to extract data isn't working properly.

I've emailed both the author of the app and the support address listed in the README and gotten no response...

Tags (1)
0 Karma

New Member

can you help me get the API connector working with Qualys? when I ran the module i get error below

Traceback (most recent call last):
File "C:\Program Files\Splunk\etc\apps\QualysGuard\bin\", line 13, in
APP_PATH = os.path.join(os.environ ['SPLUNK_HOME'], 'etc', 'apps', 'QualysGuard')
File "C:\Python27\lib\", line 423, in getitem

0 Karma


Post this as your own submission for better visibility? The 'Key Words' will pick it out thereafter?
Br, Dave

0 Karma


Thanks! I could probably download the KB with curl and write field extractions for everything, but that seems like a ton of work. I appreciate the quick reply.

Any idea why Splunk is complaining about the view template line?

0 Karma

Splunk Employee
Splunk Employee

dashboard.html is not in the app, but it is in the view system. Almost all dashboards, regardless of the app, use dashboard.html as the view template.

I do think there is a problem in the app based on your experience and the two other issues reported here on Answers, and I have alerted the folks responsible for it.

0 Karma
Get Updates on the Splunk Community!

Unify Your SecOps with Splunk Mission Control

In today’s post, I'm excited to share some recent Splunk Mission Control innovations. With Splunk Mission ...

Data Preparation Made Easy: SPL2 for Edge Processor

By now, you may have heard the exciting news that Edge Processor, the easy-to-use Splunk data preparation tool ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...