Loading

Tenable OT Security

Version 0.4.0 beta:[] (View all)
Compatible Kibana version(s) 8.16.1 or higher
9.0.0 or higher
Supported Serverless project types
What's this?
Security
Observability
Subscription level
What's this?
Basic
Level of support
What's this?
Elastic

The Elastic integration for Tenable OT Security enables real-time monitoring and analysis of operational technology security events within industrial environments. This integration collects data from Tenable OT Security platform to provide visibility into cyber threats, malicious insider activities, and human errors.

Assets: Assets represent the inventory of devices and systems monitored by Tenable OT Security, including their properties, classifications, and security posture.

Events: Events are notifications generated by Tenable OT Security to alert on potentially harmful activities in the industrial network, categorized by severity and type.

System_Logs: System logs provides detailed records of events, activities, and changes occurring within the OT environment. These logs are critical for monitoring, auditing, and investigating security incidents. They capture data from various OT assets, such as PLCs (Programmable Logic Controllers), RTUs (Remote Terminal Units), HMIs (Human-Machine Interfaces), and other industrial devices.

Log in to Tenable's cloud platform to generate an API key. This key allows applications to authenticate with Tenable's API without requiring a session.

To generate an API key, please refer to the API documentation here

The API Key will be visible once, when it is created. It must be provided when creating the integration policy.

Assets documents can be found by setting the following filter: event.dataset : "tenable_ot_security.assets"

ECS Field Reference

Please refer to the following document for detailed information on ECS fields.

The following non-ECS fields are used in assets documents:

Event documents can be found by setting the following filter: event.dataset : "tenable_ot_security.events"

ECS Field Reference

Please refer to the following document for detailed information on ECS fields.

The following non-ECS fields are used in events documents:

System Log documents can be found by setting the following filter: event.dataset : "tenable_ot_security.system_log"

ECS Field Reference

Please refer to the following document for detailed information on ECS fields.

The following non-ECS fields are used in system log documents: