# How to add Nessus CSV report to logstash

**URL:** <https://discuss.elastic.co/t/how-to-add-nessus-csv-report-to-logstash/50470>\
**Category:** Logstash\
**Created:** [May 19, 2016, 4:18pm UTC](https://discuss.elastic.co/t/how-to-add-nessus-csv-report-to-logstash/50470 "2016-05-19T16:18:53Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Abe\_Bazouie](https://avatars.discourse-cdn.com/v4/letter/a/f17d59/32.png) [@Abe\_Bazouie](https://discuss.elastic.co/u/Abe_Bazouie)\
**Post date:** [May 19, 2016, 4:18pm UTC](https://discuss.elastic.co/t/how-to-add-nessus-csv-report-to-logstash/50470/1 "2016-05-19T16:18:53Z")

</div>

Hi guys

I am kind of new in ELK. I am trying to add CSV file which is Nessus report to logstash in order to analyze them.  
What I have done is I create a .conf file in logstash but when I try to run logstash -f configfile.conf , It gave my tons of error regarding that logstash cannot parse the csv file correctly.

`input {  
file {  
path =\> "/root/csvs/\*.csv"  
type =\> "core2"  
start\_position =\> "beginning"  
}  
}

filter {  
csv {  
columns =\> ["@timestamp", "interface", "bytes in", "bytes out"]  
separator =\> ","  
}  
}

output {  
elasticsearch {  
action =\> "index"  
hosts =\> "localhost"  
index =\> "logstash-%{+YYYY.MM.dd}"  
workers =\> 1  
}  
# stdout {  
# codec =\> rubydebug  
# }  
}

Please somebody tell me how can I fix that.`

Thank you,

---

<div class="post-metadata">

**Author:** ![geekpete](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/geekpete/32/20409_2.png) [@geekpete](https://discuss.elastic.co/u/geekpete)\
**Post date:** [May 20, 2016, 6:04am UTC](https://discuss.elastic.co/t/how-to-add-nessus-csv-report-to-logstash/50470/2 "2016-05-20T06:04:02Z")

</div>

Hi Abe,

Do you have a small sample of the csv file? If not that's ok, I'll generate a sample one myself.

---

<div class="post-metadata">

**Author:** ![Abe\_Bazouie](https://avatars.discourse-cdn.com/v4/letter/a/f17d59/32.png) [@Abe\_Bazouie](https://discuss.elastic.co/u/Abe_Bazouie)\
**Post date:** [May 20, 2016, 1:33pm UTC](https://discuss.elastic.co/t/how-to-add-nessus-csv-report-to-logstash/50470/3 "2016-05-20T13:33:33Z")

</div>

Hi Peter,

This is the first couple lines of my CSV file:

`Plugin ID,CVE,CVSS,Risk,Host,Protocol,Port,Name,Synopsis,Description,Solution,See Also,Plugin Output  
"10107","","","None","1.1.1.1","tcp","80","HTTP Server Type and Version","A web server is running on the remote host.","This plugin attempts to determine the type and the version of the  
remote web server.","n/a","","The remote web server type is :

Apache/2.2.1 (Red Hat)

You can set the directive 'ServerTokens Prod' to limit the information  
emanating from the server in its response headers."  
"10107","","","None","1.1.1.1","tcp","443","HTTP Server Type and Version","A web server is running on the remote host.","This plugin attempts to determine the type and the version of the  
remote web server.","n/a","","The remote web server type is :`

Thank you,  
Abe

---

<div class="post-metadata">

**Author:** ![Abe\_Bazouie](https://avatars.discourse-cdn.com/v4/letter/a/f17d59/32.png) [@Abe\_Bazouie](https://discuss.elastic.co/u/Abe_Bazouie)\
**Post date:** [May 20, 2016, 1:36pm UTC](https://discuss.elastic.co/t/how-to-add-nessus-csv-report-to-logstash/50470/4 "2016-05-20T13:36:21Z")

</div>

I change my config file to this, but nothing changes 😔

`input {  
file {  
path =\> "/root/csvs/\*.csv"  
start\_position =\> "beginning"  
}  
}

filter {  
csv {  
columns =\> [  
"Plugin ID",  
"CVE","CVSS",  
"Risk","Host",  
"Protocol",  
"Port",  
"Name",  
"Synopsis",  
"Description",  
"Solution",  
"See Also",  
"Plugin Output"  
]  
separator =\> ","  
remove\_field =\> ["message"]  
}  
date {  
match =\> ["time", "ISO8601"]  
}  
}

output {  
elasticsearch {  
action =\> "index"  
hosts =\> "localhost"  
index =\> "logstash-%{+YYYY.MM.dd}"  
workers =\> 1  
}  
# stdout {  
# codec =\> rubydebug  
# }  
}

`

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [May 20, 2016, 4:06pm UTC](https://discuss.elastic.co/t/how-to-add-nessus-csv-report-to-logstash/50470/5 "2016-05-20T16:06:08Z")

</div>

When you post source data or code in this app, surround the text with triple backticks.

About your problem:  
Do you have newlines a field data?  
If so, I don't the CSV library that we use can cope with newlines in field data as it assumes that the text before a newline is a full CSV line with the correct number of commas etc.

---

<div class="post-metadata">

**Author:** ![geekpete](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/geekpete/32/20409_2.png) [@geekpete](https://discuss.elastic.co/u/geekpete)\
**Post date:** [May 22, 2016, 11:55pm UTC](https://discuss.elastic.co/t/how-to-add-nessus-csv-report-to-logstash/50470/6 "2016-05-22T23:55:00Z")

</div>

That newline point is a good one, can you confirm if any new line chars exist inside the fields of your CSV?

Also, do you have examples of the errors it was throwing?

---

<div class="post-metadata">

**Author:** ![a003708](https://avatars.discourse-cdn.com/v4/letter/a/47e85d/32.png) [@a003708](https://discuss.elastic.co/u/a003708)\
**Post date:** [July 19, 2016, 6:20am UTC](https://discuss.elastic.co/t/how-to-add-nessus-csv-report-to-logstash/50470/7 "2016-07-19T06:20:57Z")

</div>

Hi,

I am also facing same problem with Nessus data. Were you able to parse it correctly?

Thanks

---

<div class="post-metadata">

**Author:** ![Abe\_Bazouie](https://avatars.discourse-cdn.com/v4/letter/a/f17d59/32.png) [@Abe\_Bazouie](https://discuss.elastic.co/u/Abe_Bazouie)\
**Post date:** [July 29, 2016, 8:02pm UTC](https://discuss.elastic.co/t/how-to-add-nessus-csv-report-to-logstash/50470/8 "2016-07-29T20:02:05Z")

</div>

Hi guys,

I just want to check out is anybody has an answer for my question?  
I need to import nessus report log (csv file) to ELK somehow. I am going to leave couple lines of csv file, might be helpful.

`  
89082,CVE-2016-0799,9.3,High,1.1.1.1,tcp,443,OpenSSL 1.0.2 \< 1.0.2g Multiple Vulnerabilities (DROWN),The remote service is affected by multiple vulnerabilities.,"According to its banner, the remote host is running a version of  
OpenSSL 1.0.2 prior to 1.0.2g. It is, therefore, affected by the  
following vulnerabilities :

- A key disclosure vulnerability exists due to improper  
handling of cache-bank conflicts on the Intel  
Sandy-bridge microarchitecture. An attacker can exploit  
this to gain access to RSA key information.  
(CVE-2016-0702)

- A double-free error exists due to improper validation of  
user-supplied input when parsing malformed DSA private  
keys. A remote attacker can exploit this to corrupt  
memory, resulting in a denial of service condition or  
the execution of arbitrary code. (CVE-2016-0705)

- A NULL pointer dereference flaw exists in the  
BN\_hex2bn() and BN\_dec2bn() functions. A remote attacker  
can exploit this to trigger a heap corruption, resulting  
in the execution of arbitrary code. (CVE-2016-0797)

- A denial of service vulnerability exists due to improper  
handling of invalid usernames. A remote attacker can  
exploit this, via a specially crafted username, to leak  
300 bytes of memory per connection, exhausting available  
memory resources. (CVE-2016-0798)

- Multiple memory corruption issues exist that allow a  
remote attacker to cause a denial of service condition  
or the execution of arbitrary code. (CVE-2016-0799)

- A flaw exists that allows a cross-protocol  
Bleichenbacher padding oracle attack known as DROWN  
(Decrypting RSA with Obsolete and Weakened eNcryption).  
This vulnerability exists due to a flaw in the Secure  
Sockets Layer Version 2 (SSLv2) implementation, and it  
allows captured TLS traffic to be decrypted. A  
man-in-the-middle attacker can exploit this to decrypt  
the TSL connection by utilizing previously captured  
traffic and weak cryptography along with a series of  
specially crafted connections to an SSLv2 server that  
uses the same private key. (CVE-2016-0800)",Upgrade to OpenSSL version 1.0.2g or later.,"[https://www.openssl.org/news/secadv/20160301.txt](https://www.openssl.org/news/secadv/20160301.txt)  
[https://www.openssl.org/news/cl102.txt](https://www.openssl.org/news/cl102.txt)  
[https://drownattack.com/](https://drownattack.com/)  
[https://www.drownattack.com/drown-attack-paper.pdf","](https://www.drownattack.com/drown-attack-paper.pdf%22,%22)  
Banner : Apache/2.4.17 (Win32) OpenSSL/1.0.2d PHP/5.6.14  
Reported version : 1.0.2d  
Fixed version : 1.0.2g  
"`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:45am UTC](https://discuss.elastic.co/t/how-to-add-nessus-csv-report-to-logstash/50470/9 "2017-07-06T04:45:52Z")

</div>


