Tenable Nessus
Enable Plugin Debugging and Audit Trails
Use this section when troubleshooting false positives, authentication errors, or compliance checks. Apply these settings before running the scan.
To enable plugin debugging and audit trails for Tenable Nessus:
-
Create or edit your scan policy.
-
Go to Advanced. If the screen shows Scan Type, set it to Custom.
-
Scroll down to the Debug Settings section:
-
Save and run the scan.
-
Ensure the scan has completed with plugin debugging and audit trails enabled:
-
Select the scan to view the scan details.
-
In the upper right corner, look for the Audit Trail button next to the Configure button.
-
In the plugin results, search for the Debugging Log Report plugin.
If the Audit Trail button or the Debugging Log Report plugin are not visible, try these steps again to enable plugin debugging and audit trails.
-
Collect Scan Results
Use this section after the scan has finished. These files allow support to replay the scan results with full diagnostic data.
To collect scan results for Tenable Nessus:
-
Ensure the scan has finished with Plugin Debugging and Audit Trails enabled.
-
Select the scan, and in the upper right corner, click Export.
-
Select the Nessus DB format.
Note: Set a secure password when prompted. You must provide this password to Tenable Support.
-
Download the file and submit it to your support case.
Collect Debug Logs
Use this section when troubleshooting software crashes, service failures, or installation errors.
-
GUI Method (Nessus 8.x and later): Go to https://<nessus_ip>:8834 > Settings. In the upper-right corner, click Download Logs. Select Extended as the debug log type, then click Download.
-
CLI (Windows): Run as Admin: "C:\Program Files\Tenable\Nessus\nessuscli.exe" bug-report-generator. Choose Full Mode.
-
CLI (Linux): Run as Root: /opt/nessus/sbin/nessuscli bug-report-generator. Choose Full Mode.
-
CLI (macOS): Run as Root: /Library/Nessus/run/sbin/nessuscli bug-report-generator.




