Tenable Vulnerability Management Logs (Beta)

Connecting Tenable Vulnerability Management logs in your Panther Console

Overview

Tenable Vulnerability Management log ingestion is in open beta starting with Panther version 1.79, and is available to all customers. Please share any bug reports and feature requests with your Panther support team.

Panther supports pulling vulnerability logs directly from Tenable.

How to onboard Tenable Vulnerability Management logs to Panther

To onboard Tenable logs, you will generate an API key in Tenable, then set up a source in Panther.

Step 1: Create an API key in Tenable

  1. Log in to Tenable.

  2. Click Settings > My Account.

  3. Click API Keys > Generate > Continue.

    • Make note of your access key and secret key, as you will use them in the next step.

Step 2: Create a Tenable Log Source in Panther

  1. In the left-side navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for "Tenable Nessus," then click its tile.

  4. In the slide-out panel, click Start Setup. In the new source creation flow in the Panther Console, a slide-out panel with a "Tenable Nessus" title is shown. There is an arrow drawn from the Tenable Nessus tile to the Start Setup button in the upper right corner.

  5. Enter a descriptive name, then click Setup.

  6. Enter the Access Key and Secret Key you generated in the previous step.

  7. Click Setup. You will be directed to a success screen:

    The success screen reads, "Everything looks good! Panther will now automatically pull & process logs from your account"
    • You can optionally enable one or more Detection Packs.

    • The Trigger an alert when no events are processed setting defaults to YES. We recommend leaving this enabled, as you will be alerted if data stops flowing from the log source after a certain period of time. The timeframe is configurable, with a default of 24 hours.

      The "Trigger an alert when no events are processed" toggle is set to YES. The "How long should Panther wait before it sends you an alert that no events have been processed" setting is set to 1 Day

Supported log types

Required fields in the schema are listed as "required: true"

Tenable.Vulnerability

The following defines the Tenable Vulnerability log schema:

Last updated

Was this helpful?