All Apps and Add-ons

Qualys VM App for Splunk Enterprise: Why are Qualys data input scripts not listed under data inputs?

rahul_jasrotia
Path Finder

Hi All,

I have installed the latest version of Qualys VM App for Splunk enterprise, as well as the ta-qualyscloudplatform needed in order to bring the Aualys data into Splunk. I have successfully configured the App and the TA, but somehow the scripts that bring the data from the server listed under Settings->Data Inputs are not coming, and hence, I am not able to retrieve any data.

This was working fine with the previous Qualys app that I had on my Forwarder. Does anyone have a clue regarding this? I have followed the exact steps written in the documentation provided with the TA. Looking for a reply.

0 Karma
1 Solution

rahul_jasrotia
Path Finder

Hi All,
Got in touch with the app developer from Qualys, this app should be installed on the Indexer and then you would find the configurations as mentioned in the supporting doc. Still not sure why it won't work on the Heavy Forwarder since we have more than 2 indexers on our test and production servers and that would involve installing the app on every indexer.
I am in touch with the developer for this as well.

One more thing is to be very sure that the account that you're using is active and there is internet access on the server you;re configuring the app because that was the case with me.

View solution in original post

0 Karma

rahul_jasrotia
Path Finder

Hi All,
Got in touch with the app developer from Qualys, this app should be installed on the Indexer and then you would find the configurations as mentioned in the supporting doc. Still not sure why it won't work on the Heavy Forwarder since we have more than 2 indexers on our test and production servers and that would involve installing the app on every indexer.
I am in touch with the developer for this as well.

One more thing is to be very sure that the account that you're using is active and there is internet access on the server you;re configuring the app because that was the case with me.

0 Karma

Lindaiyu
Path Finder

Hello rahul_jasrotia,

I got the same situation as you did.
Try the url directly "http://your splunk url/en-US/manager/launcher/data/inputs/qualys"
And you will find the page and you need to set them enable.

Hope it work for you.
Thanks,
Daiyu

Lindaiyu
Path Finder

Hello rahul_jasrotia,

I got the same situation as you did.
Try the url directly "http://your splunk url/en-US/manager/launcher/data/inputs/qualys"
And you will find the page and you need to set them enable.

Hope it work for you.
Thanks,
Daiyu

rahul_jasrotia
Path Finder

Hi Lindaiyu,
Thanks yes i was able to see the scripts on the link mentioned by you.
But somehow they are not executing even after trying to make them run 4-5 times. Any idea what can be the reason for the same?

0 Karma

Lindaiyu
Path Finder

you talk about the "interval"?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...