All Apps and Add-ons

How to import Nessus reports and see results

evang_26
Communicator

Hello users,

I recently installed Splunk add-on for Nessus hoping that it would be easy to somehow upload reports (even automatically) to compare results etc.

However, it seems that I cannot find how to do it.

Could you please help me a bit?

Kind regards,
Evangelos

1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

digging this one out of the archives...

  1. configure nessus or tenable security center to export xml reports into a spool directory
  2. point the add-on for nessus at this directory. It will parse the reports into splunk-friendly data.
  3. you may also want to configure the directory where the add-on for nessus will output the data, default is a local Splunk's input spool.

View solution in original post

0 Karma

lvsteche
New Member

With the default settings, the Nessus report files must be placed in the $SPLUNK_HOME/etc/apps/Splunk_TA_nessus/spool directory. The report files must be exported to the "dot nessus" XML format and have a file extension of .nessus.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

digging this one out of the archives...

  1. configure nessus or tenable security center to export xml reports into a spool directory
  2. point the add-on for nessus at this directory. It will parse the reports into splunk-friendly data.
  3. you may also want to configure the directory where the add-on for nessus will output the data, default is a local Splunk's input spool.
0 Karma

bachube
New Member

You need to use a forwarder.

0 Karma

evang_26
Communicator

So, none of you have any clue regarding this question?

Regards,
Evangelos

0 Karma
Get Updates on the Splunk Community!

Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...