Iam trying to integrate the Splunk Add-on tenable to collect scan details from Nessus. Unfotunately, no data has been collected. Here is what I confirmed to do:
1- I installed the add-on on my heavy forwarder and configured the correct index=nessus.
2- I also installed the add-on on the search head cluster as the guide suggested after deleting both "eventgen.conf" & "inputs.conf". (Splunk Add-on for Tenable, Splunk Docs)
3- Moreover, I ensured to get the correct keys from Nessus tenable when configuring the add-on on Splunk.
(How_To_Guide_Tenable.io_Splunk_v2.pdf)
4- The indexers have the correct index.
5- Firewall ports have been allowed.
By running a tcpdump on my Heavyforwarder, I couldn't see any packages sent/received between it and the Nessus server. However, I manged to find two repetitive errors in the Nessuslog file as follow:
@Mystica856 the few times I did run into the above issue was due to a bad API or Secret Key. Hopefuly when you generated your key you copied it down from Nessus. If you do have to pull new keys make sure that you copy them down in a safe place and try adding them back to both Host and Plugin on the HF configuration page.
My fix was : rm -r /opt/nessus/var/nessus/www/, then reinstall nessus : maybe it's useless... (makepkg -si) and then sudo systemctl restart nessusd. => Maybe there is something in pkg to fix to overwrite /opt/nessus/var/nessus/www/ (such as deleting "www" ?) or just print the "maybe you sould delete www so that nessus creates it again ?)
" Version MismatchA version mismatch has been detected between the UI (v. 10.5.2) and web server (v. 10.5.4). Continuing with the login process may cause inadvertent errors. If you experience any issues, please confirm the following:"
3a8082e126