All Apps and Add-ons

Hurricane Labs Add-On for QUALYS: Why is no data coming in from API?

smith6a7
Explorer

I changed the app settings on the indexer (which is also the search head) to include api credentials and all proper settings enabled, I do not see any data. Must I place a forwarder on the appliance itself somehow?

0 Karma
1 Solution

smith6a7
Explorer

Got data to come in. Now trying to pull CVE data in using built in script and getting the following error. Any suggestions?

View solution in original post

0 Karma

smith6a7
Explorer

Got data to come in. Now trying to pull CVE data in using built in script and getting the following error. Any suggestions?

0 Karma

smith6a7
Explorer

sudo bash /opt/splunk/etc/apps/TA-qualys/bin/update_qualys_kb.sh
Traceback (most recent call last):
File "./update_qualys_kb.py", line 48, in
cfg = get_splunk_config("qualys", "api")
File "./update_qualys_kb.py", line 20, in get_splunk_config
env["LD_LIBRARY_PATH"] = os.path.join(env["SPLUNK_HOME"], "lib")
KeyError: 'SPLUNK_HOME'

0 Karma

mcmaster
Communicator

Try running that like so:

sudo /opt/splunk/bin/splunk cmd /opt/splunk/etc/apps/TA-qualys/bin/update_qualys_kb.sh

You need to run this from within the Splunk environment in order for certain functionality to be available. The above command will do that.

Let us know if that helps.

smith6a7
Explorer

This did the job! Thank you. However, can I expect the job that runs at 4:15am each night to work as it should? It does not seem to work properly (as of last night).

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...