If you are using the TA Tenable do you need to create a props.conf file under and put the regex described by Giuseppe?
local karim$ pwd
/Applications/Splunk/etc/apps/Splunk_TA_nessus/local
local karim $ ls
inputs.conf
215:local karim $ more inputs.conf
[monitor:///Applications/Splunk/etc/apps/Splunk_TA_nessus/spool]
disabled = false
host = 127.0.0.1
sourcetype = CVE_2017
please advise
Thanks
Karim
... View more