Integrate Tenable Security Center with Oomnitza to gain visibility of hosts.
Information about the hosts, including modification time, OS information, identification, and seen information, is synced with Oomnitza.
This integration leverages the Hosts API. For further information, see Tenable Security Center API Documentation: Hosts.
Information
Credentials
For information on adding your Tenable Security Center credentials to Oomnitza, refer to Adding your Tenable Security Center credentials to Oomnitza.
API URL
Before you run the integration, you will be asked to supply your full API URL. Your URL will be in the format: https://sc.mycompany.org
Creating an asset integration
- In Oomnitza, click Configuration> Integrations> Overview.
- Click Block view
- Scroll down to the Extended section for asset integrations.
- Click NEW INTEGRATION.
- Select the integration in the sidebar.
- Click ADD.
Integration details overview
More information is provided about the following fields to help you complete the integration:
Software data
Depending on the asset integration, an option might be available to ingest desktop software information such as the name and version of the software installed on an asset. To view the software information in Oomnitza, you must have the software module.
Installation types
- Cloud. Store credentials in the Oomnitza cloud.
- Local. Store credentials locally. If you want to sync Oomnitza with vendor applications that require AWS or OAUTH authentication, select cloud as the type of installation. Local installations don't support AWS and OAuth authentication.
Integration preferences
- Create & Update. Add and update records.
- Create only. Add records.
- Update only. Update records.
Integration details
To review or update the integrations details, click Edit .
When you edit the Integration details section, you can select the name or names of integration contacts. Integration contacts will receive an in-app notification and an email, when the integration fails, when the integration fails to complete within 24 hours, or when the scheduled integration fails to run.
- Update the integration name.
- Select an installation type.
- For integration preferences, select an option.
- Enter the name of the integration user.
Credential details
If you selected Cloud as the installation type, choose one of the following options:
- Select the credentials that were created for the integration.
- Edit the credentials that were created for the integration.
- Create new credentials
Scheduling the integration
By default, data is synced once every day. Change the interval or the time so that the data is streamed when your system isn't busy.
- Click Edit
.
- Make and save your changes.
Mapping fields to Oomnitza
To map the fields to Oomnitza, click Edit .
Select Edit integration to add rules for syncing data.
Filtering integration results.
Click SMART MAPPING.
You can add new fields to your integration by selecting Add new field on the mapping page.
Creating custom API fields.
Creating custom mappings
Map the Tenable SC fields to Oomnitza fields and create custom mappings to get the user information that you need.
To take advantage of workflows, ensure you map the following fields to Oomnitza:
Complete the following actions:
- Click Smart Mapping to automatically detect appropriate mapping fields. Values from the integration can also be dragged to the appropriate field on the Oomnitza side, or selected from the integration field dropdown.
- Create a custom mapping for the ID. Complete the following steps:
- Click the down arrow on the field.
- Select Add new Oomnitza field.
- Change the name of the field to Tenable SC ID.
- Select the Unique checkbox.
- Click CREATE.
- Assign a sync key to a unique field, such as the ID.
- Click UPDATE.
Standard Oomnitza mappings
The following fields can be mapped to Oomnitza:
First Seen
ID
IP Address
MAC Address
Name
OS
Operating System
TenableUUID
UUID
acr
aes
lastSeen
modifiedTime
netBiosWorkgroup
repID
source
systemType
Launching the integration
Your integration is in Draft mode until the required mandatory fields are added. When added, click Launch to activate your integration.
If you selected Cloud as the installation type when creating the integration, see Running an extended integration
If you selected Local as the installation type when creating the integration, see Running an extended integration locally.
Viewing data ingested by Oomnitza
Viewing ingested asset data
For asset integrations, click Hardware. If the asset integration also ingests software data, click Software.
Viewing ingested user data
For user integrations, click People. If you chose the option to ingest User and SaaS user data, click Software > SaaS, click the SaaS app, and then click the Users tab.
Comments
0 comments
Please sign in to leave a comment.