TheHive-Project / TheHive-Project/Cortex
Nessus analyzer config...
Nobody has claimed this yet.
- Dominant language
- Scala
- Stars
- 1.6k
- Forks
- 264
- PR merge metrics
- No merged PRs in 30d
Description
Request Type
Bug
Work Environment
| Question | Answer |
|---|---|
| OS version (server) | CentOS |
| OS version (client) | OSX |
| Cortex version / git hash | 2.x, hash of the commit |
| Package Type | RPM |
| Browser type & version | Chrome Version 79.0.3945.130 (Official Build) (64-bit) |
Problem Description
I have a working integration between Patrowl and Nessus Professional. I used the same config but get the following error when running the analyzer agains a single IP address:
Scanner error: Expecting value: line 1 column 1 (char 0)
Steps to Reproduce
- In organization, enable Nessus_2_0 analyzer
- url: http://10.1.1.190:8834/
- login: admin
- Password: ******** (verified via Nessus console and Patrowl)
- Policy: NESSUS_POLICY_NETWORK_SCAN
- Allowed_network: 10.0.0.0/8 172.20.0.0/16 (on two separate entries)
Complementary information
In Organizations -> Analyzers -> Nessus_2_0 there is an Edit button (the one I used originally) but under Organizations -> Analyzers Config -> Nessus there is also an Edit button but it doesn't share the same information. For troubleshooting I entered the same information but I would like to know which one takes precedence and in which case the other is used?

Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the Nessus_2_0 analyzer and compare its settings under Organizations → Analyzers with Organizations → Analyzers Config → Nessus. Reproduce the single-IP scan using the listed Nessus policy and network ranges, then trace the source of “Expecting value: line 1 column 1 (char 0)”; done means the configuration precedence is documented and the scan no longer fails.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- scala
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100