Getting Data In

Qualysguard splunk - No data

crossap
Path Finder

Hi,

I am in the process of setting up the Qualys app for splunk but unfortunately cannot receive any data.

I have logged the issue with Qualys for investigation but wondered if anyone else had come across the issue?

I am using the latest app and Splunk has been upgraded to the latest version (Running on Win2k12)

The setup of the application itself has been done correctly eg: API Server, User being used can authenticate and has the API enabled on the account, Scripts set to run every 60 secs for testing.

I have managed to find this one entry in the splunk logs

ERROR ExecProcessor - Couldn't start command ""C:\Program Files\Splunk\etc\apps\qualys_splunk_app\bin\qualys_detection_logger.sh"": The operation completed successfully.

0 Karma
1 Solution

lukeh
Contributor

According to the documentation, the app only supports a "Computer with MacOS or Linux"

https://apps.splunk.com/app/2654/#/documentation

The error you posted shows a script ending with .sh which is for a Unix system, aka MacOS or Linux.

All the best,

Luke.

View solution in original post

paul_DLB
New Member

Is there already a version for Windows2k12 ? I think a lot of splunk users are running on windows.

0 Karma

lukeh
Contributor

According to the documentation, the app only supports a "Computer with MacOS or Linux"

https://apps.splunk.com/app/2654/#/documentation

The error you posted shows a script ending with .sh which is for a Unix system, aka MacOS or Linux.

All the best,

Luke.

crossap
Path Finder

Hi Luke,

thanks for your response.

I am off to build a Linux server 🙂

0 Karma

lukeh
Contributor

That is what I like to hear 🙂

L.

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...