Tenable.io
Integration points
Protocol | Information collected | Used for |
---|---|---|
Tenable.io API | Vulnerability scan data | Security and Compliance |
Tenable.io API Integration
FortiSIEM can pull vulnerability scan data from Tenable.io Cloud Service via Tenable.io API.
Tenable.io scan data contains vulnerabilities found on a host. Each host vulnerability is converted into a separate FortiSIEM event with event type TenableIO-Vuln-Detected.
Configuring Tenable.io Cloud Service
Create an API Key to be used for FortiSIEM communication.
- Login to your Tenable.io portal using your account.
- Create API Key for use in FortiSIEM:
- For administrative user.
- Click Settings > User.
- In User table, click the name of the User you want to edit.
- Click the API Keys tab in the generate and click Generate.
- Click Save.
- For regular user:
- Click My Account.
- Click the API Keys tab in the generate and click Generate.
- Click Save.
Configuring FortiSIEM
Use the API Key and Secret in previous step to enable FortiSIEM access.
- Login to FortiSIEM.
- Go to ADMIN > Setup > Credential.
- Click New to create a Tenable.io credential:
- Choose Device Type = Tenable.io Tenable (Vendor = Tenable, Model = Tenable.io).
- Choose Access Protocol = TenableIO API.
- Choose Pull Interval = 5 minutes.
- Choose Account, Access Key and Secret Key obtained from Tenable.io portal (see Configuring Tenable.io Cloud Service)
- Choose the Organization if it is an MSP deployment and the same credential is to be used for multiple customers
- Click Save.
- Enter an IP range to Credential Association:
- Set Hostname = cloud.tenable.com
- Select the credential created in step 3.
- Click Save.
- Select the entry in step 4 and click Test Connectivity.
- After Test Connectivity succeeds, an entry will be created in ADMIN > Setup > Pull Events corresponding to this event pulling job. FortiSIEM will start to pull events from Tenable.io portal using the API.
To test for received Tenable.io events:
- Go to ADMIN > Setup > Pull Events.
- Select the Tenable.io entry and click Report.
The system will take you to the Analytics tab and run a query to display the events received from Tenable.io in the last 15 minutes. You can modify the time interval to get more events.