Splunk Enterprise Security

Why is the data not writing to my index after having installed and configured the splunk add on for tenable?

mcorrigan
New Member

I have installed the Splunk add on for Tenable on my Enterprise Security server and no data is being written to the index.

There are no errors in the splunk_ta_nessus_tenable_sc.log file.

The account that is being used to communicate to the security center is successfully logging into the security center server and the account can view data in security center.
I am running 6.6.0 of Splunk and 5.1.3 of the add-on.

Any suggestions?

Thanks.

0 Karma

cstump_splunk
Splunk Employee
Splunk Employee

When troubleshooting any data ingestion issue, track down where the data is being transmitted and received. For instance, in this scenario, we know that the Tenable add-on needs to be installed on the Search Head and a Heavy Forwarder, and can be installed on the indexer (http://docs.splunk.com/Documentation/AddOns/released/Nessus/InstalltoSearchHead#Where_to_install_thi...).

We should first check to see if the tenable data is leaving the Heavy Forwarder:
index=_internal host=<Heavy_Forwarder> source=*metrics* group=per_sourcetype_thruput series=<Tenable_sourcetype> | timechart sum(kb) by series span=15min

The visualization here we show you when and if your tenable data is being sent from the forwarder. If there are no results from this search, this is an indication that there is something wrong with the input. In that case, check out the heavy forwarder's splunkd.log file.
If there are results with this search, then all is good on the Forwarder side. In this case, run a similar search for the Indexer :
index=_internal host=<Indexer> source=*metrics* group=per_sourcetype_thruput series=<Tenable_sourcetype> | timechart sum(kb) by series span=15min
If there is no data here then it could be an indication that there the data is getting lost in transmission (possibly by a Firewall). If there are results here, then check to see that the tenable data is going into the index you expect it to and that you are searching for it correctly.

There are other things that could be going wrong in the process but start there.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...