Splunk Search

Tenable Add-On for Splunk- How can I filter the results based on the scan name?

osasfrancis
Path Finder

For the latest version, Version 5.2.4, I have vulnerability data coming in from Tenable.SC. How can I filter the results based on the scan name? Cannot seem to figure it out. I remember in previous versions, we could leverage scan_result_info.name, but not in this latest version.

Any thoughts is appreciated.

Thanks

0 Karma

osasfrancis
Path Finder

I am using Version 5.2.4. Yes, the field does not exist on this version, but it once did on older versions. Just cannot filter data based on scan name.

0 Karma

etoombs
Path Finder

I've never seen this field. Which version of the Tenable Add-On are you using? What version of Tenable.sc?

0 Karma

osasfrancis
Path Finder

I am using Version 5.2.4. Yes, the field does not exist on this version, but it once did on older versions. Just cannot filter data based on scan name.

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...