Splunk Search

How can I get actual host names or IPs for Rapid7 Nexpose data in Splunk?

dshpritz
SplunkTrust
SplunkTrust

The Nexpose app uses the API to get data into Splunk. The problem is that the vulnerability events don't have actual host names or IPs in them, instead they have a list of the IDs of the hosts. As that ID is not referenced anywhere else in Splunk (for example, in a lookup file), the vulnerability events are almost useless. Is there a way to get the actual hostnames or IP addresses of the hosts?

Thanks.

Tags (1)

mln21
Engager

Hi dshpritz and thanks for your question. I work on the technical alliances team at Rapid7. Our current plan is to incorporate this feature into a future release of the Rapid7 Nexpose for Splunk App. To do this we are planning leveraging the Common Information Model. In addition to the asset names or the IP addresses, what other kinds of information would you find useful? We would love to hear feedback on the app and ways to make it better.

Thanks,
Martin

stinnett
New Member

Hi Martin,

Is there any eta for this release?

Thanks,

Jon

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...