Troubleshooting

Here are some troubleshooting tips.

Looking for Logs?

Qualys logs are populated in Splunk’s index “_internal”. Use this search to find logs:

index=_internal source="$SPLUNK_HOME/var/log/splunk/TA_qualys_cloud_connector_*.log"

The add-on generates a separate log file for each modular input, organized by input type. This allows you to isolate logs for a specific data input when multiple inputs are running simultaneously.

Use the following Search Processing Language (SPL) to find app-specific logs:

index=_internal source="$SPLUNK_HOME/var/log/splunk/TA-Qualys-Cloud-Connector/vmdr/vmdrtest.log*"   

index=_internal source="$SPLUNK_HOME/var/log/splunk/TA-Qualys-Cloud-Connector/was/wastest.log*"

Use the data input name as per your records

Troubleshooting the Connector Setup

  • Be sure to enter the proper API Server URL for the configuration.
  • Verify that you can reach the API from the Splunk Search Head where you have installed the Qualys App for Splunk Enterprise (no firewall or other infrastructure).
  • Be sure the Qualys user account you use to connect has API access. Edit the user account in the Qualys UI, then select the API access checkbox in the user settings. If you are not able to see this option, contact Qualys Support or your Technical Account Manager.

Updated Qualys Universal Technology Add-on (TA) for Splunk Settings does not reflect.

If you are not able to see the updated Qualys Universal Technology Add-on (TA) for Splunk Setup page, clear the cache and perform a hard reload to view changes.

Issue

Possible Cause

Resolution

ModuleNotFoundError in log

Add-on not installed correctly

Reinstall the add-on; verify lib/ directory is present

Input fails immediately after enabling

Python version mismatch

Verify Splunk is using Python 3.9 or later ($SPLUNK_HOME/bin/python3 --version)

Settings saved, but not taking effect

Splunk restart required

Restart Splunk after saving configuration changes for the first time

Data input is visible, but not running

Input is disabled, or the interval is too long

Check the Actions toggle in Inputs; verify interval value

URL to the Qualys API Server

The Qualys API URL you should use for API requests depends on the Qualys platform where your account is located.

Click here to identify your Qualys platform and get the API URL.

  • You can find the API server URL for your account.
  • Log in to your Qualys account and go to Help > About.

    You can view this information under the Security Operations Center (SOC).

    about-2

HTTP 503 – KV Store Initialization Failed

Cause

Occurs after a Splunk upgrade or due to a temporary KV Store startup issue.

Solution

Restart the Splunk service : $SPLUNK_HOME/bin/splunk restart