Tenable.SC Connector Unable to Pull SC Queries (Tenable Version)

Zach40
Tera Contributor

Hi all, I am unable to pull SC Queries from my Tenable.SC environment into my ServiceNow Tenable Connector.

  

I have tried the following:

  • Ensuring I have the Security Manager role in Tenable.SC
  • Ensuring I have the proper roles in ServiceNow to configure the Tenable.SC connector
  • I have the Tenable Connector connection successfully connected
  • I re-authenticated, downloaded credentials, queries, plugins, and full plugins for the connector
  • I have the latest ServiceNow Tenable Connector and Tenable for Assets plugins
  • I have a compatible version of Tenable.SC per documentation requirements

 

Any Suggestions, and is there a specific way I should be setting up my Tenable.SC query for the Tenable for Assets pull?

16 REPLIES 16

For the SN-built Tenable integration, a Fixed job is run first that then triggers the Open job:

find_real_file.png

 

but.... I'm not a Tenable admin... so tell me more about the "Within the last day" condition?

 

@Chris McDevitt  We are using the Tenable built integration (v4.0.0) so it is a bit different but does import both cumulative and fixed vulnerabilities. Although interestingly, it runs the Fixed import after the Cumulative import:
find_real_file.png

Within Tenable.sc, you can filter on the last time the vulnerability was observed (seen) on a system, so we are using that setting to pull in everything that is still open "within the last day" after scans run:

find_real_file.png

If I don't set this filter, the number of vulnerabilities is significantly larger.  There is also a separate filter for "Vulnerability Discovered" where you can set the same date settings.

Tenable tracks both of these for each vulnerability:

find_real_file.png

Ashutosh Munot1
Kilo Patron
Kilo Patron

Hi,

We contacted our Tenable team and have asked them to setup a query for us in tenable. We also found that it takes sometime to sync and also credentials should be properly set up.


You can see the errors in Integrations scans and also in ecc queue. Also check the MID server ecc queue payload size.


Thanks,
Ashutosh

Nirmalya Datta1
Kilo Expert

I have faced a similar issue but I have resolved the issue using a workaround. These are the methodologies and two approaches that can be followed to resolve the issue:- (I have followed the first approach as it is quick)

Approach 1:-

1) Navigate to Vulnerability Response --> Administration --> Setup Assistant --> Integration Configuration --> Scanner Integrations (Ensure the plugin "Vulnerability Response Integration with Tenable" is enabled. I used version 2.0.4)

2) Setup the Integration Instances and while setting it up, in the fourth step, click on "Finish" without selecting a filter query (of course if the drop down is not fetching any query. If available then select from the drop down)

3) Once done, navigate to Tenable Vulnerability Integration --> Administration --> Integration Instances --> Click on the Integration Instance setup in step 2

4) On a new browser tab/window, If you have access to Tenable, login into Tenable, open the intended filter query from within Tenable navigating through the path Analysis --> Query and click on the down arrow beside the gear icon towards the right hand side of the query in the query list and click on "View". Once you are viewing the details of the filter query in tenable, copy the value of ID from there for that filter query which is unique for that query. If you do not have access to tenable, as you tenable administrators to provide you the ID of the filter query

5) Navigate back to the browser tab/window where you had opened the integration instance within ServiceNow in step 3. In the related list of "Integration Instance Parameters" for that integration instance, open the parameter of "query_id" and put the copied ID from step 4 in the "Value" field and save the parameter record

6) Ensure that your mid server user is active and not locked and mid server is up and running and connection from mid-server to tenable instance is fine (if you are using a mid-server) and then execute a vulnerability integration for that integration instance. It should be working even without configuring the filter query from the Setup Assistant.

That should configure the corresponding filter query in tenable immediately for that integration instance that you are configuring.

 

Approach 2:-

1) Ensure that your mid server user is active and not locked out and the mid server is up and running (if you are using a mid-server)

2) If the drop down in the fourth step is not appearing while configuring the integration instance, in the fourth step, keep the query blank and leave it for sometime and let the queries sync through the connecting user

3) Re-visit the connector after sometime and check again in the fourth step is the drop down of the query filters are available. If yes, select it, if not come back again after sometime and iterate the process.

Nic Nagtzaam
Mega Guru

There are ongoing issues with the Tenable plugins and Tenable SC. we have had similar issues where we couldn't create CI to SC groups. Since upgrading to the latest Tenable Plugins majority of the functionality has actually disappeared.