Splunk Enterprise

Splunk not syncing Tenable Data

nrs011
Observer

Hello,

My Splunk Enterprise is no longer syncing Tenable Data. Please help.

Thank you.

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

We need a lot more information before we can help.

When did this start? What changed around that time (Splunk, Tenable, firewalls)? Have you checked splunkd.log?

What is the path for Tenable data to get into Splunk (UF, HF, etc.)? Have you verified all instances in the path are up?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...