Initial public release of TA-Nessus-CIM-Mapper.
This Technology Add-on normalizes Tenable Nessus Professional JSON scan events to align with Splunk's Common Information Model (CIM), specifically the 'Vulnerabilities' data model.
category
cve
cvss
score (v2 and v3)severity
(lowercased for CIM compatibility)signature
vendor_product
dest
and dvc
fields
Event type:
nessus_vulnerabilities
applied to sourcetype nessus:json
Tags applied:
vulnerability
report
Eval expressions for derived fields like url
and cvss
Compatible with Splunk Cloud and Splunk Enterprise
A separate script is available to extract and send vulnerabilities from Nessus Professional
Release date: 2025-08-08
Author: Francis Segura
Initial public release of TA-Nessus-CIM-Mapper.
This Technology Add-on normalizes Tenable Nessus Professional JSON scan events to align with Splunk's Common Information Model (CIM), specifically the 'Vulnerabilities' data model.
category
cve
cvss
score (v2 and v3)severity
(lowercased for CIM compatibility)signature
vendor_product
dest
and dvc
fields
Event type:
nessus_vulnerabilities
applied to sourcetype nessus:json
Tags applied:
vulnerability
report
Eval expressions for derived fields like url
and cvss
Compatible with Splunk Cloud and Splunk Enterprise
A separate script is available to extract and send vulnerabilities from Nessus Professional to Splunk using HEC (HTTP Event Collector).
It includes checkpointing support to avoid duplicates.
Repository:
👉 https://github.com/Bl4ck0xday/nessus_splunk_checkpoint
See README.md for detailed instructions on installation and validation.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.