To complete the installation process, you must complete the setup for the Tenable Add-on for Splunk.
Before you begin:
Required User Role: Administrator
You must have your Tenable.io API keys.
Note: For your Tenable.io integration:
- Generate an API key in Tenable.io to complete the configuration. See the Tenable.io user guide for instructions on how to generate an API key. Do not use this API key for any other third-party or custom-built application or integration. It must be unique for each installed instance of the integration.
To set up the Tenable Add-on for Splunk:
- Log in to the heavy forwarder where you installed the Tenable Add-on for Splunk.
In the left navigation bar, click Tenable Add-on for Splunk.
Click the Configuration tab.
Click the Add button.
A new window appears:
Enter the necessary information for each field. The following table describes the available options.
Input Parameters Description Account Name (Required) The unique name for each Tenable data input. Tenable Account Type (Required) The type of Tenable account - Tenable.io, Tenable.sc API Keys, or Tenable.sc Certificate Address (Required) The hostname or IP address for Tenable.io. Verify SSL Certificate If enabled, Splunk verifies the SSL certificate in Tenable.io. Access Key (Required) Tenable.io API access key. Secret Key (Required) Your Tenable.io API secret key. Proxy Enable
Enables the plugin to collect Tenable.io data via a proxy server. If you select this option, the plug- in prompts you to enter the following:
- Proxy Type - the type of proxy used.
- Proxy Host - the hostname or IP address of the proxy server.
- Proxy Port - the port number of the proxy server.
- Proxy Username - the username for an account that has permissions to access and use the proxy server.
- Proxy Password - the password associated with the username you provided.
- To complete the configuration, click Add.
- Create an Input for the Tenable Add-On for Splunk.