Splunk Enterprise Security

Why is the data not writing to my index after having installed and configured the splunk add on for tenable?

mcorrigan
New Member

I have installed the Splunk add on for Tenable on my Enterprise Security server and no data is being written to the index.

There are no errors in the splunk_ta_nessus_tenable_sc.log file.

The account that is being used to communicate to the security center is successfully logging into the security center server and the account can view data in security center.
I am running 6.6.0 of Splunk and 5.1.3 of the add-on.

Any suggestions?

Thanks.

0 Karma

cstump_splunk
Splunk Employee
Splunk Employee

When troubleshooting any data ingestion issue, track down where the data is being transmitted and received. For instance, in this scenario, we know that the Tenable add-on needs to be installed on the Search Head and a Heavy Forwarder, and can be installed on the indexer (http://docs.splunk.com/Documentation/AddOns/released/Nessus/InstalltoSearchHead#Where_to_install_thi...).

We should first check to see if the tenable data is leaving the Heavy Forwarder:
index=_internal host=<Heavy_Forwarder> source=*metrics* group=per_sourcetype_thruput series=<Tenable_sourcetype> | timechart sum(kb) by series span=15min

The visualization here we show you when and if your tenable data is being sent from the forwarder. If there are no results from this search, this is an indication that there is something wrong with the input. In that case, check out the heavy forwarder's splunkd.log file.
If there are results with this search, then all is good on the Forwarder side. In this case, run a similar search for the Indexer :
index=_internal host=<Indexer> source=*metrics* group=per_sourcetype_thruput series=<Tenable_sourcetype> | timechart sum(kb) by series span=15min
If there is no data here then it could be an indication that there the data is getting lost in transmission (possibly by a Firewall). If there are results here, then check to see that the tenable data is going into the index you expect it to and that you are searching for it correctly.

There are other things that could be going wrong in the process but start there.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...