- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Password of Splunk user account in qualys got expired, we have reset the password now, new credentials are working fine with the GUI (https://qualysguard.qg2.apps.qualys.com/fo/login.php).
However, the Splunk add-on(TA-QualysCloudPlatform) is still not accepting new credentials, and logs are not flowing to Splunk, what might be the issue.
Steps Followed:
Updated new password in TA-QualysCloudPlatform and restarted Splunk
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In order to update the changes successfully into the Qualys TA for Splunk, please follow the below steps:
1)From Settings> Data Inputs disable the TA Inputs
2)Delete passwords.conf file.
3)Reboot the splunk instance.
4)Go to TA config in Splunk UI and give the credentials again.
5)Check if the passwords.conf file created
6)Enable TA inputs from data Inputs
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In order to update the changes successfully into the Qualys TA for Splunk, please follow the below steps:
1)From Settings> Data Inputs disable the TA Inputs
2)Delete passwords.conf file.
3)Reboot the splunk instance.
4)Go to TA config in Splunk UI and give the credentials again.
5)Check if the passwords.conf file created
6)Enable TA inputs from data Inputs
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for your response. Which server contains the `passwords.conf` file for Qualys TA (TA-QualysCloudPlatform)? I couldn't find it on the Heavy Forwarder (HF).
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You have to either re-enter the credentials and delete the old, or reinstall the app.
Check this documentation: : https://community.splunk.com/t5/Getting-Data-In/Having-trouble-setting-up-TA-QualysCloudPlatform-App...
