Skip to main content

Tenable.io

Visualize Tenable.io scans, findings, vulnerabilities, and container findings, map Tenable.io users to employees, and monitor changes through queries and alerts.

Installation

For this integration, you will need an Access Key and Secret Key from Tenable Vulnerability Management. The API key owner must have the Administrator role to use the bulk export APIs that power this integration.

info

See Generate API Keys in the Tenable documentation for instructions on generating your access and secret keys.

Configuration in JupiterOne

To install the Tenable integration in JupiterOne, navigate to the Integrations tab and select Tenable. Click New Instance to begin configuring your integration.

Creating an instance requires the following:

  • Your Access Key and Secret Key from Tenable Vulnerability Management.

Optionally, to enable container image scanning via the Tenable Cloud Security API, provide a Cloud Security API Key (see Data Volume Configuration below).

Click Create once all values are provided to finalize the integration.

Next steps

Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.

Data Volume Configuration

The following settings control which data the integration collects and over what time range.

Data Filtering Options

FieldDescriptionDefaultOptions
Included Vulnerability SeveritiesVulnerability severity levels to include in ingestion.All severitiesInfo, Low, Medium, High, Critical
Included Vulnerability Modification TypesFilters vulnerabilities by whether their state has been modified by a rule (recasted or accepted). Select "None" to include only unmodified findings.All modification typesNone, Recasted, Accepted
Included Vulnerability StatesLifecycle states of vulnerability findings to include.All statesOpen, Reopened, Fixed
Compliance Findings - ResultsCompliance check result statuses to include in the ingestion.All resultsPASSED, FAILED, WARNING, SKIPPED, UNKNOWN, ERROR
Compliance Findings - StatesLifecycle states of compliance findings to include.All statesOPEN, REOPENED, FIXED
Assets - Licensed FilterRestricts asset export to licensed or non-licensed assets only. Leave at "No filter" to export all assets.No filterNo filter, Include only licensed, Include only non-licensed

Ingestion Windows

FieldDescriptionDefault
Compliance Findings - Last Seen (days)Number of days back to include compliance findings that were last seen.15

Advanced Configuration

FieldDescriptionDefault
Base URLThe base URL for the Tenable Vulnerability Management API. Change this only if you use a regional or on-premises endpoint.https://cloud.tenable.com
Cloud Security API KeyAPI key for the Tenable Cloud Security (formerly Ermetic) GraphQL API. Required to ingest container images and reports. If not provided, the integration falls back to the main Access Key.
Cloud Security Base URLThe base URL for the Tenable Cloud Security API. Use a regional value such as us.app.ermetic.com or eu.app.ermetic.com if applicable.https://global.app.ermetic.com