Splunk Enterprise Security

Why is the data not writing to my index after having installed and configured the splunk add on for tenable?

mcorrigan
New Member

I have installed the Splunk add on for Tenable on my Enterprise Security server and no data is being written to the index.

There are no errors in the splunk_ta_nessus_tenable_sc.log file.

The account that is being used to communicate to the security center is successfully logging into the security center server and the account can view data in security center.
I am running 6.6.0 of Splunk and 5.1.3 of the add-on.

Any suggestions?

Thanks.

0 Karma

cstump_splunk
Splunk Employee
Splunk Employee

When troubleshooting any data ingestion issue, track down where the data is being transmitted and received. For instance, in this scenario, we know that the Tenable add-on needs to be installed on the Search Head and a Heavy Forwarder, and can be installed on the indexer (http://docs.splunk.com/Documentation/AddOns/released/Nessus/InstalltoSearchHead#Where_to_install_thi...).

We should first check to see if the tenable data is leaving the Heavy Forwarder:
index=_internal host=<Heavy_Forwarder> source=*metrics* group=per_sourcetype_thruput series=<Tenable_sourcetype> | timechart sum(kb) by series span=15min

The visualization here we show you when and if your tenable data is being sent from the forwarder. If there are no results from this search, this is an indication that there is something wrong with the input. In that case, check out the heavy forwarder's splunkd.log file.
If there are results with this search, then all is good on the Forwarder side. In this case, run a similar search for the Indexer :
index=_internal host=<Indexer> source=*metrics* group=per_sourcetype_thruput series=<Tenable_sourcetype> | timechart sum(kb) by series span=15min
If there is no data here then it could be an indication that there the data is getting lost in transmission (possibly by a Firewall). If there are results here, then check to see that the tenable data is going into the index you expect it to and that you are searching for it correctly.

There are other things that could be going wrong in the process but start there.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...