We want to forward all events to Nessus LCE Server (Nessus Security Center).
Since we have all Splunk Servers deployed on Windows, we cannot use the Nessus LCE Agent which is only available for some Linux Distros.
So we've tried to forward the events using the outputs.conf (tried tcpout and syslog).
Unfortunately the LCE Server is not able to normalize these events since they aren't sent in a proper syslog format.
One Event is splittet into multiple lines. I'm not sure if it's a splunk or a nessus lce issue.
Anybody who has a similar setup with splunk and nessus? Any hints?
Thx & Regards
you can find all the configuration for your need
About the format problem , you could send not raw data but parsed data (sendCookedData=True) so you can structure events as you prefer.