Tenable Macros
To modify the macro definition:
Tenable Index Macro
- Go to Settings > Advance search > Search Macros.
-
In the App section, select Tenable App for Splunk.
-
Click the search icon.
Results appear.
-
Click get_tenable_index.
The get_tenable_index macro page appears.
- In the Definition entry field, update the definition to index=INDEX_NAME. The INDEX_NAME should be the same name entered when you created the data input.
-
Click Save.
Tenable Source Types
- Go to Settings > Advance search > Search Macros.
-
Click get_tenable_sourcetype.
Note: The default macro definition is sourcetype=(tenable:sc:vuln OR tenable:io:vuln).