Hello,
Does Tenable not send remediated vulnerabilities to Splunk after it has reported it once? The situation is as follows:
A Host ABC had it's CVE-1234-5678 patched in April 2023, for which there is a record in the index. But after that there is not a single time that the Remediated vulnerability has been reported. It only reports on the open ones from there on. I tried enabling the "Historical reporting of remediated vulnerabilities" - but that still isn't helping. As a result, we consider that host to have the vulnerability as "Open".
Is this the expected behaviour? I thought this setting would report the remediated vulnerabilities each time the scan runs?
The Tenable TA only pulls in events with new information ( a new scan date, change in a field or status) each time it accesses the data. Once an item is pulled in, it doesn't pull it a second time. That means if you scan half of your devices on Monday and half of your devices on Tuesday, you need to search looking back 2 days to see all of your current data. Once an individual finding has been pulled in, it doesn't grab the same item again unless there is a change.