Tenable.io Integration

Instructions for Integration Between Tenable.io & InsightCloudSec

The Tenable integration provides InsightCloudSec the ability to communicate with assets in your Tenable accounts. As an example, you can send high priority security alerts when a Tenable Agent has not checked in recently or it has no Agent configured.

Prerequisites & Requirements

At this time we only support Tenable.io.

  • This guide assumes that you have installed and linked Nessus Agents to your instances.
  • The Tenable.io Agent must have had at least one completed scan run after the integration is configured.
  • A Tenable user with Administrator access.

For general information about InsightCloudSec Integrations (editing and deleting), refer to the Integrations Overview page.

If you need help with this integration, contact us through the Customer Support Portal.

Tenable Setup

1. Get Credentials to your Tenable.io user (Admin required) and access your Tenable dashboard.

  • Click on the user icon in the top right.
  • Click on "My Account".
  • Click on "API Keys" and click "Generate"
  • Save the API Keys.
654654 788788

2. To update InsightCloudSec navigate to "Administration --> Integrations".

14921492

Tenable Integration

3. Select "Edit" on the Tenable.io card and provide the following:

  • API Key (Access Key)
  • Secret Key
10041004

Tenable Integration Form

4. Click "Save" when you have completed the form for the Tenable.io integration.

Tenable Filters

The following Query Filters are currently available for use with the Tenable.io integration:

  • Instance With Tenable.io Agent Configured
  • Instance With Tenable.io Agent Not Configured
  • Instance With Tenable.io Agent Last Checkin Threshold

For example, you can use the Query Filter Instance With Tenable.io Agent Configured to show what instances have the Tenable Agent installed. The following illustration shows one instance has the Tenable Agent installed.

17071707

If you are interested in using these Query Filters with automation, InsightCloudSec includes Bot actions that you may be interested in using as part of your Tenable.io integration.

Tenable Agent Harvesting

Instance Agents are harvested every hour. However you can manually enqueue the job to run with the following steps:

1. Navigate to "Administration --> System Administration" and select the "Background Jobs" tab.

2. Search for "Agent".

3. Select the "Enqueue Now" option for the 'ResourceAgentHourlyProcessor' job.

12591259

Enqueue Tenable "ResourceAgentProcessor" Job Manually


Did this page help you?