Security

integration with nessus server outside network?

abdullahalhabba
Explorer

How to integration with nessus server Knowing that this server exist in cloud network environment, means this server contains public IP and Splunk servers contains privet IP, is there any method that helps me in that, for example am i use URL for success integration?

Please I want full details?
Thanks my friends.

0 Karma

Richfez
SplunkTrust
SplunkTrust

abdullahalhabbash,

[EDIT: I realized that I was coming off inappropriately negative, so I reworded to make it more fair]

The Splunk Add-on for Tenable should do what you need.

NOTES:
Your concern about it having a public address and your own Splunk server having a private address is of no concern. Think of it like your PC/Mac having a private address, yet you can still go to Google or Amazon.

There are instructions for setting up the connection here, but you may need to read through this answer about getting data from tenable.io, too.

While this app really should work OK, it is under development right now. There have been some issues in the past that are mostly resolved, but if you get it sort of working but it's flaky or failure prone, make sure you are on the latest version and if the problem still persists open a ticket with Splunk. They can often help get it working, as long as you've done due diligence with your configs and things.

I hope this helps!
Happy Splunking!
-Rich

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...