Debug Log Reporting
Plugin #84239: Debugging Log Report reports the logs that other plugins generate.
The Tenable Nessus scanner writes debug logs for the Delinea Secret Server integration during the scan. The debug logging settings in Tenable Nessus control the debugging log report output.
The integration writes to log files named after the credential plugin that invoked it:
-
SSH: ssh_settings.nasl
-
Windows (SMB): logins.nasl
-
Database: database_settings.nasl
-
VMware vCenter: vmware_vcenter_settings.nasl
-
VMware ESXi: vmware_soap_settings.nasl
-
Nutanix Prism Central: nutanix_settings.nasl
When you troubleshoot the Delinea Secret Server PAM integration, examine the debugging logs for the entries related to the specific credential in use:
-
SSH: ssh_settings.nasl~Delinea Secret Server
-
Windows (SMB): logins.nasl~Delinea Secret Server
-
Database: database_settings.nasl~Delinea Secret Server
-
VMware vCenter: vmware_vsphere_vcenter_settings.nbin~Delinea Secret Server
-
VMware ESXi: vmware_soap_settings.nbin~Delinea Secret Server
-
Nutanix Prism Central: nutanix_settings.nasl~Delinea Secret Server
What Do the Logs Contain?
The debug logs record the full integration lifecycle for each scan, including:
-
Configuration settings loaded from the scan policy, with sensitive values masked.
-
The authentication method used and whether authentication succeeded.
-
The Delinea Secret Server API requests and the HTTP response status.
-
Whether the integration found the secret and parsed its value successfully.
-
Cache hit and miss information for repeated credential retrievals.
-
Any errors the Delinea Secret Server API returned, including authentication failures and secret-not-found responses.
Common Reasons for Credentialed Checks Showing a "no" Status
-
The Delinea Secret Server authentication type does not have an Access Role that grants read access to the specified secret.
-
The Delinea Secret Server host is unreachable from the scanner because of a firewall, an incorrect hostname, or an incorrect port.
-
The path for the authentication URL is incorrect or misspelled.
-
An invalid JSON parameters file is provided for the SSH Signed Certificates vault type.
-
The Secrets Engine URL contains an incorrect role during the creation or signing of a public key, when you use the SSH Signed Certificates vault type.
-
SSL certificate verification fails because the Delinea Secret Server integration instance uses a self-signed certificate and Verify SSL Certificate is enabled.