Skip to content
Notifications
Clear all

Step-by-step: Integrating Vuln scans from Tenable into Elastic for a unified view.

1 Posts
1 Users
0 Reactions
5 Views
(@diego_h)
Reputable Member
Joined: 4 months ago
Posts: 122
Topic starter   [#1182]

Hi everyone. I'm trying to get vulnerability data from our Tenable.io scans into Elastic Security. The goal is to have all our security findings in one place.

I've seen mentions of the Tenable API and the Elastic integrations, but I'm unsure about the specific steps. Could someone outline the process? Mainly, I'm curious about:
* Pushing data from Tenable to Elastic vs. pulling it from Elastic.
* If we need to use Logstash or if the Elastic Agent can handle it.
* How the vulnerabilities actually appear in the Elastic SIEM interface once set up.

Any pointers to avoid common setup pitfalls would be really helpful.


Still learning.


   
Quote