Loading

Tenable OT Security

Version 2.1.0 (View all)
Subscription level
What's this?
Basic
Developed by
What's this?
Elastic
Ingestion method(s) API
Minimum Kibana version(s) 9.1.4
8.19.2

The Elastic integration for Tenable OT Security enables real-time monitoring and analysis of operational technology security events within industrial environments. This integration collects data from Tenable OT Security platform to provide visibility into cyber threats, malicious insider activities, and human errors.

Agentless integrations allow you to collect data without having to manage Elastic Agent in your cloud. They make manual agent deployment unnecessary, so you can focus on your data instead of the agent that collects it. For more information, refer to Agentless integrations and the Agentless integrations FAQ. Agentless deployments are only supported in Elastic Serverless and Elastic Cloud environments. This functionality is in beta and is subject to change. Beta features are not subject to the support SLA of official GA features.

Assets: Assets represent the inventory of devices and systems monitored by Tenable OT Security, including their properties, classifications, and security posture.

Events: Events are notifications generated by Tenable OT Security to alert on potentially harmful activities in the industrial network, categorized by severity and type.

System_Logs: System logs provides detailed records of events, activities, and changes occurring within the OT environment. These logs are critical for monitoring, auditing, and investigating security incidents. They capture data from various OT assets, such as PLCs (Programmable Logic Controllers), RTUs (Remote Terminal Units), HMIs (Human-Machine Interfaces), and other industrial devices.

Log in to Tenable's cloud platform to generate an API key. This key allows applications to authenticate with Tenable's API without requiring a session.

To generate an API key, please refer to the API documentation here

The API Key will be visible once, when it is created. It must be provided when creating the integration policy.

Assets documents can be found by setting the following filter: event.dataset : "tenable_ot_security.assets"

ECS Field Reference

Please refer to the following document for detailed information on ECS fields.

The following non-ECS fields are used in assets documents:

Event documents can be found by setting the following filter: event.dataset : "tenable_ot_security.events"

ECS Field Reference

Please refer to the following document for detailed information on ECS fields.

The following non-ECS fields are used in events documents:

System Log documents can be found by setting the following filter: event.dataset : "tenable_ot_security.system_log"

ECS Field Reference

Please refer to the following document for detailed information on ECS fields.

The following non-ECS fields are used in system log documents:

This integration includes one or more Kibana dashboards that visualizes the data collected by the integration. The screenshots below illustrate how the ingested data is displayed.