To complete the installation process, you must complete the setup for the Tenable Add-on for Splunk.

Before you begin:

Required User Role: Administrator

  • You must have your API keys.

    Note: For your integration:

    • Generate an API key in to complete the configuration. See the user guide for instructions on how to generate an API key. Do not use this API key for any other third-party or custom-built application or integration. It must be unique for each installed instance of the integration.

To set up the Tenable Add-on for Splunk:

  1. Log in to the heavy forwarder where you installed the Tenable Add-on for Splunk.
  2. In the left navigation bar, click Tenable Add-on for Splunk.

  3. Click the Configuration tab.

  4. Click the Add button.

    A new window appears:

  1. Enter the necessary information for each field. The following table describes the available options.

    Input Parameters Description
    Account Name (Required) The unique name for each Tenable data input.
    Tenable Account Type (Required) The type of Tenable account -, API Keys, or Certificate
    Address (Required) The hostname or IP address for
    Verify SSL Certificate If enabled, Splunk verifies the SSL certificate in
    Access Key (Required) API access key.
    Secret Key (Required) Your API secret key.
    Proxy Enable

    Enables the plugin to collect data via a proxy server. If you select this option, the plug- in prompts you to enter the following:

    • Proxy Type - the type of proxy used.
    • Proxy Host - the hostname or IP address of the proxy server.
    • Proxy Port - the port number of the proxy server.
    • Proxy Username - the username for an account that has permissions to access and use the proxy server.
    • Proxy Password - the password associated with the username you provided.
  2. To complete the configuration, click Add.

Next steps