Getting Data In

How do I integrate Tenable with Splunk?

danielbb
Motivator

I see multiple Tenable Apps and TAs in Splunkbase, which one should I use to get Tenable data in?   

Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Tenable is a company. The right add-on depends on which Tenable products/services you are using.

0 Karma

livehybrid
SplunkTrust
SplunkTrust

I would recommend the Tenable TA at https://splunkbase.splunk.com/app/4060 for getting the data in to Splunk which uses Splunk Modular Inputs to connect to your Tenable service and pull the data.

You can also download the Tenable App (https://splunkbase.splunk.com/app/4061) which is different to the TA in that it is more focussed on visualising the Tenable data. This utilises the data in the TA and the data you have ingested.

Both of these Splunk apps are built and supported by Tenable themselves but assume you but assumes you're using Tenable's feature products - there are separate Splunkbase apps made by Tenable for WAS / EASM if you are using these products.

Please let me know how you get on and consider upvoting/karma this answer if it has helped.
Regards

Will

0 Karma

luizlimapg
Path Finder

Hi @danielbb 

I used the TA below for a long time and it worked well.
https://splunkbase.splunk.com/app/4060 

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...