Splunk Enterprise Security

What's your favorite vuln scanner to use with Splunk?

daniel333
Builder

All,

What's your favorite Vulnerability scanner to use with Splunk? That is what have you seen generate the best logs and metrics for Splunk data models and CIM?

0 Karma

jobobreck
New Member

With all due respect to the poster stating that vuln scan data is "state data" and should remain resident outside of Splunk, that response is very short sided and under-appreciates why one would want the data there.

Tenable products work well for vuln scanning, but they're less awesome for policy-based scans. Qualys has a better policy scanner, but it too has issues if you want to import into Splunk. If you're looking for a cost-effective for more simplistic data processing environments (ie 1 data center), and can roll your own reporting, Nessus Pro is a great solution.

0 Karma

jg91
Path Finder

Hello, If you want a commercial product Nessus is so good, but if you want a free Vuln scanner, you can use OpenVAS, it's has an App for Splunk but it's not released on splunkbase and it is accessible from OpenVAS website (google for it!) and also you can send OpenVAS scan results with syslog to Splunk and parse it manually.

0 Karma

ivanspl
New Member

Hi! Can you add link to OpenVAS App for Splunk? (yes, google delete :C)

Thank you!

0 Karma

jg91
Path Finder

Hi, you can find it at Tools section in doc subdomain of greenbone website.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @daniel333,
if you're speaking about a probe like Nessus, we usually use Tenable Nessus and SecurityCenter integrated with Splunk and we have good results from the App in appbase ( https://splunkbase.splunk.com/app/4061/ ) and creating our own searches.

Ciao.
Giuseppe

0 Karma

starcher
Influencer

None, vuln data is state and belongs in a database. Trying to turn Splunk into a vuln management tool when it is based on time series events leads to pain. The best compromise is run reports of key vulns and send only that to Splunk for alerting and correlation. Just don’t try to feed everything in.

Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...