diff --git a/packages/tenable_io/_dev/build/docs/README.md b/packages/tenable_io/_dev/build/docs/README.md index ac6b60761cd..973fde71695 100644 --- a/packages/tenable_io/_dev/build/docs/README.md +++ b/packages/tenable_io/_dev/build/docs/README.md @@ -18,7 +18,7 @@ The Tenable Vulnerability Management integration collects logs for five types of **Vulnerability** is used to retrieve all vulnerabilities on each asset, including the vulnerability state. See more details in the API documentation [here](https://developer.tenable.com/reference/exports-vulns-request-export). -**Scan** is used to retrieve details about existing scans and scan details, including scan statuses, assigned targets, and more. See more details in the API documentation for [Scan](https://developer.tenable.com/reference/scans-list) and [Scan Details](https://developer.tenable.com/reference/was-v2-scans-details). +**Scan** is used to retrieve details about existing scans and scan details, including scan statuses, assigned targets, and more. See more details in the API documentation for [Scan](https://developer.tenable.com/reference/scans-list) and [Scan Details](https://developer.tenable.com/reference/scans-details). ## Compatibility diff --git a/packages/tenable_io/_dev/deploy/docker/files/config.yml b/packages/tenable_io/_dev/deploy/docker/files/config.yml index 1d16d1231d9..605f6e4028f 100644 --- a/packages/tenable_io/_dev/deploy/docker/files/config.yml +++ b/packages/tenable_io/_dev/deploy/docker/files/config.yml @@ -71,22 +71,18 @@ rules: {"id":226,"name":"Targeted Scans","type":"custom","custom":1,"unread_count":0,"default_tag":0} ] } - - path: /was/v2/scans/195 + - path: /scans/195 methods: ["GET"] responses: - status_code: 200 body: | - { - "scan_id":"195","user_id":"53e1d711-f18f-4a75-a86e-1c47bccff1b7","config_id":"a772daba-3d6d-412c-8ee0-3279b19650b2","target":"http://192.0.2.119","created_at":"2020-02-05T23:11:49.342Z","updated_at":"2020-02-05T23:22:15.510Z","requested_action":"start","status":"completed","metadata":{"queued_urls":0,"scan_status":"stopping","crawled_urls":1,"queued_pages":0,"audited_pages":1,"request_count":74,"response_time":0} - } - - path: /was/v2/scans/423 + {"info":{"owner":"jdoe@contoso.com","name":"Client Discovery","no_target":false,"folder_id":226,"control":true,"user_permissions":128,"schedule_uuid":"11c56dea-as5f-65ce-ad45-9978045df65ecade45b6e3a76871","edit_allowed":true,"scanner_name":null,"policy":null,"shared":true,"object_id":195,"tag_targets":[],"hostcount":1,"uuid":"a456ef1c-cbd4-ad41-f654-119b766ff61f","status":"completed","scan_type":"remote","targets":"192.0.2.57","alt_targets_used":false,"pci-can-upload":false,"scan_start":1683282785,"timestamp":1683283158,"is_archived":false,"scan_end":1683283158,"haskb":true,"hasaudittrail":true,"scanner_start":null,"scanner_end":null,"acls":[{"permissions":128,"owner":1,"display_name":"jdoe@contoso.com","name":"jdoe@contoso.com","id":1,"type":"user"}]},"history":[{"history_id":1000195,"owner_id":1,"creation_date":1683282785,"last_modification_date":1683283158,"uuid":"a456ef1c-cbd4-ad41-f654-119b766ff61f","type":"remote","status":"completed","scheduler":0,"alt_targets_used":false,"is_archived":false}],"hosts":[{"asset_id":5,"host_id":5,"hostname":"192.0.2.57","progress":"100-100/200-200","scanprogresscurrent":100,"scanprogresstotal":100,"numchecksconsidered":100,"totalchecksconsidered":100,"severitycount":{"item":[{"count":156,"severitylevel":0},{"count":1,"severitylevel":1},{"count":6,"severitylevel":2},{"count":3,"severitylevel":3},{"count":0,"severitylevel":4}]},"severity":166,"score":3766,"info":156,"low":1,"medium":6,"high":3,"critical":0,"host_index":0}],"vulnerabilities":[{"count":3,"plugin_id":34220,"plugin_name":"Netstat Portscanner (WMI)","severity":0,"plugin_family":"Port scanners","vuln_index":1}]} + - path: /scans/423 methods: ["GET"] responses: - status_code: 200 body: | - { - "scan_id":"423","user_id":"53e1d711-f18f-4a75-a86e-1c47bccff1b7","config_id":"a772daba-3d6d-412c-8ee0-3279b19650b2","target":"http://192.0.2.119","created_at":"2020-02-05T23:11:49.342Z","updated_at":"2020-02-05T23:22:15.510Z","requested_action":"start","status":"completed","metadata":{"queued_urls":0,"scan_status":"stopping","crawled_urls":1,"queued_pages":0,"audited_pages":1,"request_count":74,"response_time":0} - } + {"info":{"owner":"jdoe@contoso.com","name":"Client Vulnerabiltiy Scan Group B","no_target":false,"folder_id":227,"control":true,"user_permissions":128,"schedule_uuid":"1d63c64e-a5d1-df57-0ecf-9f0e288d8a45fe84bcd54e39daaf","edit_allowed":true,"scanner_name":null,"policy":null,"shared":true,"object_id":423,"tag_targets":[],"hostcount":1,"uuid":"a2389003-fec1-a45d-a45d-aece258c4133","status":"completed","scan_type":"remote","targets":"192.0.2.0/24","alt_targets_used":false,"pci-can-upload":false,"scan_start":1683043551,"timestamp":1683049400,"is_archived":false,"scan_end":1683049400,"haskb":true,"hasaudittrail":true,"scanner_start":null,"scanner_end":null,"acls":[{"permissions":128,"owner":1,"display_name":"jdoe@contoso.com","name":"jdoe@contoso.com","id":1,"type":"user"}]},"history":[{"history_id":1000423,"owner_id":1,"creation_date":1683043551,"last_modification_date":1683049400,"uuid":"a2389003-fec1-a45d-a45d-aece258c4133","type":"remote","status":"completed","scheduler":0,"alt_targets_used":false,"is_archived":false}],"hosts":[{"asset_id":3,"host_id":3,"hostname":"192.0.2.57","progress":"100-100/200-200","scanprogresscurrent":100,"scanprogresstotal":100,"numchecksconsidered":100,"totalchecksconsidered":100,"severitycount":{"item":[{"count":52,"severitylevel":0},{"count":11,"severitylevel":1},{"count":100,"severitylevel":2},{"count":58,"severitylevel":3},{"count":32,"severitylevel":4}]},"severity":253,"score":388162,"info":52,"low":11,"medium":100,"high":58,"critical":32,"host_index":0}],"vulnerabilities":[{"count":65,"plugin_id":34252,"plugin_name":"Microsoft Windows Remote Listeners Enumeration (WMI)","severity":0,"plugin_family":"Windows","vuln_index":1}]} - path: /audit-log/v1/events methods: ["GET"] query_params: diff --git a/packages/tenable_io/changelog.yml b/packages/tenable_io/changelog.yml index e4ed1ed5d30..21614b950d0 100644 --- a/packages/tenable_io/changelog.yml +++ b/packages/tenable_io/changelog.yml @@ -1,4 +1,9 @@ # newer versions go on top +- version: "4.12.1" + changes: + - description: Replace the scan details endpoint with GET /scans/{id} and remap the scan_details fields to the standard VM scan-details schema. + type: bugfix + link: https://github.com/elastic/integrations/pull/20347 - version: "4.12.0" changes: - description: Allow user configuration of maximum number of CEL executions for the asset, audit, plugin, and scan data streams. diff --git a/packages/tenable_io/data_stream/asset/sample_event.json b/packages/tenable_io/data_stream/asset/sample_event.json index d1c28d87295..078ee2fb7a9 100644 --- a/packages/tenable_io/data_stream/asset/sample_event.json +++ b/packages/tenable_io/data_stream/asset/sample_event.json @@ -1,11 +1,11 @@ { "@timestamp": "2018-12-31T22:27:58.599Z", "agent": { - "ephemeral_id": "f945f2c2-fbaf-4b93-b6ca-7d51e6a0706d", - "id": "a0570906-16fc-4c38-821f-7c3aa6ed04bb", - "name": "docker-fleet-agent", + "ephemeral_id": "d1524bb7-93f3-43e5-a4e8-691b38ada6fc", + "id": "42f9eef6-3014-478c-b828-bbcbda65cf4f", + "name": "elastic-agent-15508", "type": "filebeat", - "version": "8.12.0" + "version": "8.19.0" }, "cloud": { "availability_zone": "12", @@ -18,16 +18,16 @@ }, "data_stream": { "dataset": "tenable_io.asset", - "namespace": "ep", + "namespace": "54262", "type": "logs" }, "ecs": { "version": "8.11.0" }, "elastic_agent": { - "id": "a0570906-16fc-4c38-821f-7c3aa6ed04bb", + "id": "42f9eef6-3014-478c-b828-bbcbda65cf4f", "snapshot": false, - "version": "8.12.0" + "version": "8.19.0" }, "event": { "agent_id_status": "verified", @@ -35,7 +35,7 @@ "host" ], "dataset": "tenable_io.asset", - "ingested": "2024-04-02T09:13:00Z", + "ingested": "2026-07-27T09:27:59Z", "kind": "state", "original": "{\"acr_score\":\"3\",\"agent_names\":[],\"agent_uuid\":\"22\",\"aws_availability_zone\":null,\"aws_ec2_instance_ami_id\":\"12\",\"aws_ec2_instance_group_name\":null,\"aws_ec2_instance_id\":\"12\",\"aws_ec2_instance_state_name\":null,\"aws_ec2_instance_type\":null,\"aws_ec2_name\":null,\"aws_ec2_product_code\":null,\"aws_owner_id\":\"44\",\"aws_region\":null,\"aws_subnet_id\":null,\"aws_vpc_id\":null,\"azure_resource_id\":\"12\",\"azure_vm_id\":\"12\",\"bigfix_asset_id\":null,\"bios_uuid\":\"33\",\"created_at\":\"2017-12-31T20:40:44.535Z\",\"deleted_at\":\"2017-12-31T20:40:44.535Z\",\"deleted_by\":\"user\",\"exposure_score\":\"721\",\"first_scan_time\":\"2017-12-31T20:40:23.447Z\",\"first_seen\":\"2017-12-31T20:40:23.447Z\",\"fqdns\":[\"example.com\"],\"gcp_instance_id\":\"12\",\"gcp_project_id\":\"12\",\"gcp_zone\":\"12\",\"has_agent\":false,\"has_plugin_results\":true,\"hostnames\":[],\"id\":\"95c2725c-7298-4a44-8a1d-63131ca3f01f\",\"installed_software\":[\"cpe:/a:test:xyz:12.8\",\"cpe:/a:test:abc:7.7.3\",\"cpe:/a:test:pqr:6.9\",\"cpe:/a:test:xyz\"],\"ipv4s\":[\"89.160.20.112\"],\"ipv6s\":[],\"last_authenticated_scan_date\":\"2017-12-31T20:40:44.535Z\",\"last_licensed_scan_date\":\"2018-12-31T22:27:52.869Z\",\"last_scan_id\":\"00283024-afee-44ea-b467-db5a6ed9fd50ab8f7ecb158c480e\",\"last_scan_time\":\"2018-03-31T22:27:52.869Z\",\"last_schedule_id\":\"72284901-7c68-42b2-a0c4-c1e75568849df60557ee0e264228\",\"last_seen\":\"2018-12-31T22:27:52.869Z\",\"mac_addresses\":[],\"manufacturer_tpm_ids\":[],\"mcafee_epo_agent_guid\":null,\"mcafee_epo_guid\":null,\"netbios_names\":[],\"network_interfaces\":[{\"fqdns\":[\"example.com\"],\"ipv4s\":[\"89.160.20.112\",\"81.2.69.144\"],\"ipv6s\":[\"2a02:cf40::\"],\"mac_addresses\":[\"00-00-5E-00-53-00\",\"00-00-5E-00-53-FF\"],\"name\":\"test.0.1234\"}],\"operating_systems\":[],\"qualys_asset_ids\":[],\"qualys_host_ids\":[],\"servicenow_sysid\":null,\"sources\":[{\"first_seen\":\"2017-12-31T20:40:23.447Z\",\"last_seen\":\"2018-12-31T22:27:52.869Z\",\"name\":\"TEST_SCAN\"}],\"ssh_fingerprints\":[],\"symantec_ep_hardware_keys\":[],\"system_types\":[],\"tags\":[{\"added_at\":\"2018-12-31T14:53:13.817Z\",\"added_by\":\"ac2e7ef6-fac9-47bf-9170-617331322885\",\"key\":\"Geographic Area\",\"uuid\":\"47e7f5f6-1013-4401-a705-479bfadc7826\",\"value\":\"APAC\"}],\"terminated_at\":\"2017-12-31T20:40:44.535Z\",\"terminated_by\":\"user\",\"updated_at\":\"2018-12-31T22:27:58.599Z\"}", "type": [ @@ -162,4 +162,4 @@ "updated_at": "2018-12-31T22:27:58.599Z" } } -} \ No newline at end of file +} diff --git a/packages/tenable_io/data_stream/audit/sample_event.json b/packages/tenable_io/data_stream/audit/sample_event.json index 94875a170a1..b0a6e4e1cb2 100644 --- a/packages/tenable_io/data_stream/audit/sample_event.json +++ b/packages/tenable_io/data_stream/audit/sample_event.json @@ -1,24 +1,24 @@ { "@timestamp": "2018-12-31T01:40:07.000Z", "agent": { - "ephemeral_id": "2b353f6e-e21d-4e61-a426-9b582471c1fa", - "id": "1a70a431-df2f-4f16-9352-a30f75fb1df2", - "name": "elastic-agent-83695", + "ephemeral_id": "48852dc2-5fcd-43e2-9dcf-91f496198616", + "id": "54bb10de-7dac-4d6f-8f76-b0fa753a6755", + "name": "elastic-agent-12062", "type": "filebeat", - "version": "8.18.1" + "version": "8.19.0" }, "data_stream": { "dataset": "tenable_io.audit", - "namespace": "31446", + "namespace": "73649", "type": "logs" }, "ecs": { "version": "8.11.0" }, "elastic_agent": { - "id": "1a70a431-df2f-4f16-9352-a30f75fb1df2", + "id": "54bb10de-7dac-4d6f-8f76-b0fa753a6755", "snapshot": false, - "version": "8.18.1" + "version": "8.19.0" }, "event": { "action": "session-delete", @@ -28,7 +28,7 @@ ], "dataset": "tenable_io.audit", "id": "eaac53481de04f67bc7eeea07d2fb0f5", - "ingested": "2025-06-03T16:34:47Z", + "ingested": "2026-07-27T09:28:46Z", "kind": "event", "original": "{\"action\":\"session.delete\",\"actor\":{\"id\":\"d2667922-5a27-4c4a-9207-f591fbdc9d23\",\"name\":\"user2@example.com\"},\"crud\":\"d\",\"description\":null,\"fields\":[{\"key\":\"message\",\"value\":\"session timeout\"}],\"id\":\"eaac53481de04f67bc7eeea07d2fb0f5\",\"is_anonymous\":null,\"is_failure\":false,\"received\":\"2018-12-31T01:40:07Z\",\"target\":{\"id\":\"12d024e\",\"name\":null,\"type\":\"Session\"}}", "outcome": "success", diff --git a/packages/tenable_io/data_stream/plugin/sample_event.json b/packages/tenable_io/data_stream/plugin/sample_event.json index 793454190c6..92b9b0bcbbd 100644 --- a/packages/tenable_io/data_stream/plugin/sample_event.json +++ b/packages/tenable_io/data_stream/plugin/sample_event.json @@ -1,29 +1,29 @@ { "@timestamp": "2018-07-19T00:00:00.000Z", "agent": { - "ephemeral_id": "f945f2c2-fbaf-4b93-b6ca-7d51e6a0706d", - "id": "a0570906-16fc-4c38-821f-7c3aa6ed04bb", - "name": "docker-fleet-agent", + "ephemeral_id": "30513499-3121-45dd-8e75-67e3b042d3a1", + "id": "1fa7cf0a-419d-4967-a86b-696c132d365d", + "name": "elastic-agent-96491", "type": "filebeat", - "version": "8.12.0" + "version": "8.19.0" }, "data_stream": { "dataset": "tenable_io.plugin", - "namespace": "ep", + "namespace": "72547", "type": "logs" }, "ecs": { "version": "8.11.0" }, "elastic_agent": { - "id": "a0570906-16fc-4c38-821f-7c3aa6ed04bb", + "id": "1fa7cf0a-419d-4967-a86b-696c132d365d", "snapshot": false, - "version": "8.12.0" + "version": "8.19.0" }, "event": { "agent_id_status": "verified", "dataset": "tenable_io.plugin", - "ingested": "2024-04-02T09:13:52Z", + "ingested": "2026-07-27T09:29:35Z", "kind": "state", "original": "{\"attributes\":{\"cpe\":[\"p-cpe:/a:fedoraproject:fedora:kernel-source\",\"cpe:/o:fedoraproject:fedora_core:1\",\"p-cpe:/a:fedoraproject:fedora:kernel-BOOT\",\"p-cpe:/a:fedoraproject:fedora:kernel-debuginfo\",\"p-cpe:/a:fedoraproject:fedora:kernel\",\"p-cpe:/a:fedoraproject:fedora:kernel-doc\",\"p-cpe:/a:fedoraproject:fedora:kernel-smp\"],\"cve\":[\"CVE-2003-0984\"],\"cvss3_base_score\":0,\"cvss3_temporal_score\":0,\"cvss_base_score\":4.6,\"cvss_temporal_score\":0,\"cvss_vector\":{\"AccessComplexity\":\"Low\",\"AccessVector\":\"Local-access\",\"Authentication\":\"None required\",\"Availability-Impact\":\"Partial\",\"Confidentiality-Impact\":\"Partial\",\"Integrity-Impact\":\"Partial\",\"raw\":\"AV:L/AC:L/Au:N/C:P/I:P/A:P\"},\"default_account\":false,\"description\":\"Various RTC drivers had the potential to leak...\",\"exploit_available\":false,\"exploit_framework_canvas\":false,\"exploit_framework_core\":false,\"exploit_framework_d2_elliot\":false,\"exploit_framework_exploithub\":false,\"exploit_framework_metasploit\":false,\"exploited_by_malware\":false,\"exploited_by_nessus\":false,\"has_patch\":true,\"in_the_news\":false,\"malware\":false,\"patch_publication_date\":\"2004-01-07T00:00:00Z\",\"plugin_modification_date\":\"2018-07-19T00:00:00Z\",\"plugin_publication_date\":\"2004-07-23T00:00:00Z\",\"plugin_type\":\"local\",\"plugin_version\":\"1.17\",\"risk_factor\":\"Medium\",\"see_also\":[\"http://example.com/u?07bc9e7f\"],\"solution\":\"Update the affected packages.\",\"synopsis\":\"The remote Fedora Core host is missing a security update.\",\"unsupported_by_vendor\":false,\"vpr\":{\"drivers\":{\"age_of_vuln\":{\"lower_bound\":366,\"upper_bound\":730},\"cvss3_impact_score\":5.9,\"cvss_impact_score_predicted\":false,\"exploit_code_maturity\":\"UNPROVEN\",\"product_coverage\":\"LOW\",\"threat_intensity_last28\":\"VERY_LOW\",\"threat_recency\":{\"lower_bound\":366,\"upper_bound\":730},\"threat_sources_last28\":[\"No recorded events\"]},\"score\":5.5,\"updated\":\"2018-07-19T00:00:00Z\"},\"xref\":[\"FEDORA:2003-047\"],\"xrefs\":[{\"id\":\"2003-047\",\"type\":\"FEDORA\"}]},\"id\":13670,\"name\":\"Fedora Core 1 : kernel-2.4.22-1.2140.nptl (2003-047)\"}", "type": [ @@ -159,4 +159,4 @@ "temporal": 0 } } -} \ No newline at end of file +} diff --git a/packages/tenable_io/data_stream/scan/_dev/test/pipeline/test-scan.log b/packages/tenable_io/data_stream/scan/_dev/test/pipeline/test-scan.log index 21213de6f13..5387700bf4d 100644 --- a/packages/tenable_io/data_stream/scan/_dev/test/pipeline/test-scan.log +++ b/packages/tenable_io/data_stream/scan/_dev/test/pipeline/test-scan.log @@ -1,3 +1,3 @@ {"control":true,"creation_date":1683282785,"enabled":true,"id":195,"last_modification_date":1683283158,"legacy":false,"name":"Client Discovery","owner":"jdoe@contoso.com","policy_id":194,"read":false,"rrules":"FREQ=WEEKLY;INTERVAL=1;BYDAY=FR","schedule_uuid":"11c56dea-as5f-65ce-ad45-9978045df65ecade45b6e3a76871","shared":true,"starttime":"20220708T033000","status":"completed","template_uuid":"a1efc3b4-cd45-a65d-fbc4-0079ebef4a56cd32a05ec2812bcf","timezone":"America/Los_Angeles","has_triggers":false,"type":"remote","permissions":128,"user_permissions":128,"uuid":"a456ef1c-cbd4-ad41-f654-119b766ff61f","wizard_uuid":"32cbd657-fe65-a45e-a45f-0079eb89e56a1c23fd5ec2812bcf","progress":100,"total_targets":21,"status_times":{"initializing":2623,"pending":52799,"processing":1853,"publishing":300329,"running":15759}} {"control":true,"creation_date":1683043551,"enabled":true,"id":423,"last_modification_date":1683049400,"legacy":false,"name":"Client Vulnerabiltiy Scan Group B","owner":"jdoe@contoso.com","policy_id":422,"read":false,"rrules":"FREQ=WEEKLY;INTERVAL=1;BYDAY=TU","schedule_uuid":"1d63c64e-a5d1-df57-0ecf-9f0e288d8a45fe84bcd54e39daaf","shared":true,"starttime":"20220714T090000","status":"completed","template_uuid":"731a8e52-3ea6-a291-ec0a-d2ff0d8af595bcd788d6be818b65","timezone":"America/Los_Angeles","has_triggers":false,"type":"remote","permissions":128,"user_permissions":128,"uuid":"a2389003-fec1-a45d-a45d-aece258c4133","wizard_uuid":"731a8e52-a4d5-54f2-acd4-d2ffd7afec9645d788d6be818b65","progress":100,"total_targets":2538,"status_times":{"initializing":6099,"pending":57966,"processing":393,"publishing":240537,"running":5544031}} -{"control":true,"creation_date":1683282785,"enabled":true,"id":195,"last_modification_date":1683283158,"legacy":false,"name":"Client Discovery","owner":"jdoe@contoso.com","policy_id":194,"read":false,"rrules":"FREQ=WEEKLY;INTERVAL=1;BYDAY=FR","schedule_uuid":"11c56dea-as5f-65ce-ad45-9978045df65ecade45b6e3a76871","shared":true,"starttime":"20220708T033000","status":"completed","template_uuid":"a1efc3b4-cd45-a65d-fbc4-0079ebef4a56cd32a05ec2812bcf","timezone":"America/Los_Angeles","has_triggers":false,"type":"remote","permissions":128,"user_permissions":128,"uuid":"a456ef1c-cbd4-ad41-f654-119b766ff61f","wizard_uuid":"32cbd657-fe65-a45e-a45f-0079eb89e56a1c23fd5ec2812bcf","progress":100,"total_targets":21,"status_times":{"initializing":2623,"pending":52799,"processing":1853,"publishing":300329,"running":15759},"scan_details":{"scan_id":"7f2fc25a-bdd8-4ad4-91dd-b9563ed69560","user_id":"53e1d711-f18f-4a75-a86e-1c47bccff1b7","config_id":"a772daba-3d6d-412c-8ee0-3279b19650b2","target":"http://192.0.2.119","created_at":"2020-02-05T23:11:49.342Z","updated_at":"2020-02-05T23:22:15.510Z","requested_action":"start","status":"completed","metadata":{"queued_urls":0,"scan_status":"stopping","crawled_urls":1,"queued_pages":0,"audited_pages":1,"request_count":74,"response_time":0}}} +{"control":true,"creation_date":1683282785,"enabled":true,"id":195,"last_modification_date":1683283158,"legacy":false,"name":"Client Discovery","owner":"jdoe@contoso.com","policy_id":194,"read":false,"rrules":"FREQ=WEEKLY;INTERVAL=1;BYDAY=FR","schedule_uuid":"11c56dea-as5f-65ce-ad45-9978045df65ecade45b6e3a76871","shared":true,"starttime":"20220708T033000","status":"completed","template_uuid":"a1efc3b4-cd45-a65d-fbc4-0079ebef4a56cd32a05ec2812bcf","timezone":"America/Los_Angeles","has_triggers":false,"type":"remote","permissions":128,"user_permissions":128,"uuid":"a456ef1c-cbd4-ad41-f654-119b766ff61f","wizard_uuid":"32cbd657-fe65-a45e-a45f-0079eb89e56a1c23fd5ec2812bcf","progress":100,"total_targets":21,"status_times":{"initializing":2623,"pending":52799,"processing":1853,"publishing":300329,"running":15759},"scan_details":{"info":{"owner":"jdoe@contoso.com","name":"Client Discovery","no_target":false,"folder_id":226,"control":true,"user_permissions":128,"schedule_uuid":"11c56dea-as5f-65ce-ad45-9978045df65ecade45b6e3a76871","edit_allowed":true,"scanner_name":null,"policy":null,"shared":true,"object_id":195,"tag_targets":[],"hostcount":1,"uuid":"a456ef1c-cbd4-ad41-f654-119b766ff61f","status":"completed","scan_type":"remote","targets":"192.0.2.57","alt_targets_used":false,"pci-can-upload":false,"scan_start":1683282785,"timestamp":1683283158,"is_archived":false,"scan_end":1683283158,"haskb":true,"hasaudittrail":true,"scanner_start":null,"scanner_end":null,"acls":[{"permissions":128,"owner":1,"display_name":"jdoe@contoso.com","name":"jdoe@contoso.com","id":1,"type":"user"}]},"history":[{"history_id":1000195,"owner_id":1,"creation_date":1683282785,"last_modification_date":1683283158,"uuid":"a456ef1c-cbd4-ad41-f654-119b766ff61f","type":"remote","status":"completed","scheduler":0,"alt_targets_used":false,"is_archived":false}],"hosts":[{"asset_id":5,"host_id":5,"hostname":"192.0.2.57","progress":"100-100/200-200","scanprogresscurrent":100,"scanprogresstotal":100,"numchecksconsidered":100,"totalchecksconsidered":100,"severitycount":{"item":[{"count":156,"severitylevel":0},{"count":1,"severitylevel":1},{"count":6,"severitylevel":2},{"count":3,"severitylevel":3},{"count":0,"severitylevel":4}]},"severity":166,"score":3766,"info":156,"low":1,"medium":6,"high":3,"critical":0,"host_index":0}],"vulnerabilities":[{"count":3,"plugin_id":34220,"plugin_name":"Netstat Portscanner (WMI)","severity":0,"plugin_family":"Port scanners","vuln_index":1}]}} diff --git a/packages/tenable_io/data_stream/scan/_dev/test/pipeline/test-scan.log-expected.json b/packages/tenable_io/data_stream/scan/_dev/test/pipeline/test-scan.log-expected.json index 2e63307a9df..3377b84cecd 100644 --- a/packages/tenable_io/data_stream/scan/_dev/test/pipeline/test-scan.log-expected.json +++ b/packages/tenable_io/data_stream/scan/_dev/test/pipeline/test-scan.log-expected.json @@ -119,11 +119,16 @@ "configuration" ], "kind": "state", - "original": "{\"control\":true,\"creation_date\":1683282785,\"enabled\":true,\"id\":195,\"last_modification_date\":1683283158,\"legacy\":false,\"name\":\"Client Discovery\",\"owner\":\"jdoe@contoso.com\",\"policy_id\":194,\"read\":false,\"rrules\":\"FREQ=WEEKLY;INTERVAL=1;BYDAY=FR\",\"schedule_uuid\":\"11c56dea-as5f-65ce-ad45-9978045df65ecade45b6e3a76871\",\"shared\":true,\"starttime\":\"20220708T033000\",\"status\":\"completed\",\"template_uuid\":\"a1efc3b4-cd45-a65d-fbc4-0079ebef4a56cd32a05ec2812bcf\",\"timezone\":\"America/Los_Angeles\",\"has_triggers\":false,\"type\":\"remote\",\"permissions\":128,\"user_permissions\":128,\"uuid\":\"a456ef1c-cbd4-ad41-f654-119b766ff61f\",\"wizard_uuid\":\"32cbd657-fe65-a45e-a45f-0079eb89e56a1c23fd5ec2812bcf\",\"progress\":100,\"total_targets\":21,\"status_times\":{\"initializing\":2623,\"pending\":52799,\"processing\":1853,\"publishing\":300329,\"running\":15759},\"scan_details\":{\"scan_id\":\"7f2fc25a-bdd8-4ad4-91dd-b9563ed69560\",\"user_id\":\"53e1d711-f18f-4a75-a86e-1c47bccff1b7\",\"config_id\":\"a772daba-3d6d-412c-8ee0-3279b19650b2\",\"target\":\"http://192.0.2.119\",\"created_at\":\"2020-02-05T23:11:49.342Z\",\"updated_at\":\"2020-02-05T23:22:15.510Z\",\"requested_action\":\"start\",\"status\":\"completed\",\"metadata\":{\"queued_urls\":0,\"scan_status\":\"stopping\",\"crawled_urls\":1,\"queued_pages\":0,\"audited_pages\":1,\"request_count\":74,\"response_time\":0}}}", + "original": "{\"control\":true,\"creation_date\":1683282785,\"enabled\":true,\"id\":195,\"last_modification_date\":1683283158,\"legacy\":false,\"name\":\"Client Discovery\",\"owner\":\"jdoe@contoso.com\",\"policy_id\":194,\"read\":false,\"rrules\":\"FREQ=WEEKLY;INTERVAL=1;BYDAY=FR\",\"schedule_uuid\":\"11c56dea-as5f-65ce-ad45-9978045df65ecade45b6e3a76871\",\"shared\":true,\"starttime\":\"20220708T033000\",\"status\":\"completed\",\"template_uuid\":\"a1efc3b4-cd45-a65d-fbc4-0079ebef4a56cd32a05ec2812bcf\",\"timezone\":\"America/Los_Angeles\",\"has_triggers\":false,\"type\":\"remote\",\"permissions\":128,\"user_permissions\":128,\"uuid\":\"a456ef1c-cbd4-ad41-f654-119b766ff61f\",\"wizard_uuid\":\"32cbd657-fe65-a45e-a45f-0079eb89e56a1c23fd5ec2812bcf\",\"progress\":100,\"total_targets\":21,\"status_times\":{\"initializing\":2623,\"pending\":52799,\"processing\":1853,\"publishing\":300329,\"running\":15759},\"scan_details\":{\"info\":{\"owner\":\"jdoe@contoso.com\",\"name\":\"Client Discovery\",\"no_target\":false,\"folder_id\":226,\"control\":true,\"user_permissions\":128,\"schedule_uuid\":\"11c56dea-as5f-65ce-ad45-9978045df65ecade45b6e3a76871\",\"edit_allowed\":true,\"scanner_name\":null,\"policy\":null,\"shared\":true,\"object_id\":195,\"tag_targets\":[],\"hostcount\":1,\"uuid\":\"a456ef1c-cbd4-ad41-f654-119b766ff61f\",\"status\":\"completed\",\"scan_type\":\"remote\",\"targets\":\"192.0.2.57\",\"alt_targets_used\":false,\"pci-can-upload\":false,\"scan_start\":1683282785,\"timestamp\":1683283158,\"is_archived\":false,\"scan_end\":1683283158,\"haskb\":true,\"hasaudittrail\":true,\"scanner_start\":null,\"scanner_end\":null,\"acls\":[{\"permissions\":128,\"owner\":1,\"display_name\":\"jdoe@contoso.com\",\"name\":\"jdoe@contoso.com\",\"id\":1,\"type\":\"user\"}]},\"history\":[{\"history_id\":1000195,\"owner_id\":1,\"creation_date\":1683282785,\"last_modification_date\":1683283158,\"uuid\":\"a456ef1c-cbd4-ad41-f654-119b766ff61f\",\"type\":\"remote\",\"status\":\"completed\",\"scheduler\":0,\"alt_targets_used\":false,\"is_archived\":false}],\"hosts\":[{\"asset_id\":5,\"host_id\":5,\"hostname\":\"192.0.2.57\",\"progress\":\"100-100/200-200\",\"scanprogresscurrent\":100,\"scanprogresstotal\":100,\"numchecksconsidered\":100,\"totalchecksconsidered\":100,\"severitycount\":{\"item\":[{\"count\":156,\"severitylevel\":0},{\"count\":1,\"severitylevel\":1},{\"count\":6,\"severitylevel\":2},{\"count\":3,\"severitylevel\":3},{\"count\":0,\"severitylevel\":4}]},\"severity\":166,\"score\":3766,\"info\":156,\"low\":1,\"medium\":6,\"high\":3,\"critical\":0,\"host_index\":0}],\"vulnerabilities\":[{\"count\":3,\"plugin_id\":34220,\"plugin_name\":\"Netstat Portscanner (WMI)\",\"severity\":0,\"plugin_family\":\"Port scanners\",\"vuln_index\":1}]}}", "type": [ "info" ] }, + "related": { + "ip": [ + "192.0.2.57" + ] + }, "tags": [ "preserve_original_event", "preserve_duplicate_custom_fields" @@ -145,23 +150,109 @@ "read": false, "rrules": "FREQ=WEEKLY;INTERVAL=1;BYDAY=FR", "scan_details": { - "config_id": "a772daba-3d6d-412c-8ee0-3279b19650b2", - "created_at": "2020-02-05T23:11:49.342Z", - "metadata": { - "audited_pages": 1, - "crawled_urls": 1, - "queued_pages": 0, - "queued_urls": 0, - "request_count": 74, - "response_time": 0, - "scan_status": "stopping" + "history": [ + { + "alt_targets_used": false, + "creation_date": "2023-05-05T10:33:05.000Z", + "history_id": 1000195, + "is_archived": false, + "last_modification_date": "2023-05-05T10:39:18.000Z", + "owner_id": 1, + "scheduler": 0, + "status": "completed", + "type": "remote", + "uuid": "a456ef1c-cbd4-ad41-f654-119b766ff61f" + } + ], + "hosts": [ + { + "asset_id": 5, + "critical": 0, + "high": 3, + "host_id": 5, + "host_index": 0, + "hostname": "192.0.2.57", + "info": 156, + "low": 1, + "medium": 6, + "numchecksconsidered": 100, + "progress": "100-100/200-200", + "scanprogresscurrent": 100, + "scanprogresstotal": 100, + "score": 3766, + "severity": 166, + "severitycount": { + "item": [ + { + "count": 156, + "severitylevel": 0 + }, + { + "count": 1, + "severitylevel": 1 + }, + { + "count": 6, + "severitylevel": 2 + }, + { + "count": 3, + "severitylevel": 3 + }, + { + "count": 0, + "severitylevel": 4 + } + ] + }, + "totalchecksconsidered": 100 + } + ], + "info": { + "acls": [ + { + "display_name": "jdoe@contoso.com", + "id": 1, + "name": "jdoe@contoso.com", + "owner": 1, + "permissions": 128, + "type": "user" + } + ], + "alt_targets_used": false, + "control": true, + "edit_allowed": true, + "folder_id": 226, + "hasaudittrail": true, + "haskb": true, + "hostcount": 1, + "is_archived": false, + "name": "Client Discovery", + "no_target": false, + "object_id": 195, + "owner": "jdoe@contoso.com", + "pci-can-upload": false, + "scan_end": "2023-05-05T10:39:18.000Z", + "scan_start": "2023-05-05T10:33:05.000Z", + "scan_type": "remote", + "schedule_uuid": "11c56dea-as5f-65ce-ad45-9978045df65ecade45b6e3a76871", + "shared": true, + "status": "completed", + "targets": "192.0.2.57", + "timestamp": "2023-05-05T10:39:18.000Z", + "user_permissions": 128, + "uuid": "a456ef1c-cbd4-ad41-f654-119b766ff61f" }, - "requested_action": "start", - "scan_id": "7f2fc25a-bdd8-4ad4-91dd-b9563ed69560", - "status": "completed", - "target": "http://192.0.2.119", - "updated_at": "2020-02-05T23:22:15.510Z", - "user_id": "53e1d711-f18f-4a75-a86e-1c47bccff1b7" + "vulnerabilities": [ + { + "count": 3, + "plugin_family": "Port scanners", + "plugin_id": 34220, + "plugin_name": "Netstat Portscanner (WMI)", + "severity": 0, + "vuln_index": 1 + } + ] }, "schedule_uuid": "11c56dea-as5f-65ce-ad45-9978045df65ecade45b6e3a76871", "shared": true, diff --git a/packages/tenable_io/data_stream/scan/agent/stream/cel.yml.hbs b/packages/tenable_io/data_stream/scan/agent/stream/cel.yml.hbs index 5f8f149fb02..333e5fd9704 100644 --- a/packages/tenable_io/data_stream/scan/agent/stream/cel.yml.hbs +++ b/packages/tenable_io/data_stream/scan/agent/stream/cel.yml.hbs @@ -64,7 +64,7 @@ program: | (has(state.worklist) && size(state.worklist) > 0) ? state.worklist[0].as(scan, state.with( - request("GET", state.url.trim_right("/") + "/was/v2/scans/" + string(scan.id)).with({ + request("GET", state.url.trim_right("/") + "/scans/" + string(scan.id)).with({ "Header": { "X-ApiKeys": ["accessKey=" + state.access_key + ";secretKey=" + state.secret_key], "User-Agent": ["Integration/1.0 (Elastic; Tenable.io; Build/3.0.0)"] @@ -90,7 +90,7 @@ program: | "error": { "code": string(details_resp.StatusCode), "id": string(details_resp.Status), - "message": "GET /was/v2/scans/" + string(scan.id) + ": " + ( + "message": "GET /scans/" + string(scan.id) + ": " + ( size(details_resp.Body) != 0 ? string(details_resp.Body) : diff --git a/packages/tenable_io/data_stream/scan/elasticsearch/ingest_pipeline/default.yml b/packages/tenable_io/data_stream/scan/elasticsearch/ingest_pipeline/default.yml index 2ef3eaf333f..b2c6932a443 100644 --- a/packages/tenable_io/data_stream/scan/elasticsearch/ingest_pipeline/default.yml +++ b/packages/tenable_io/data_stream/scan/elasticsearch/ingest_pipeline/default.yml @@ -66,21 +66,94 @@ processors: formats: - yyyyMMdd'T'HHmmss - date: - field: json.scan_details.created_at - target_field: json.scan_details.created_at - if: ctx.json?.scan_details?.created_at != null && ctx.json.scan_details.created_at != '' + field: json.scan_details.info.scan_start + target_field: json.scan_details.info.scan_start + if: ctx.json?.scan_details?.info?.scan_start != null && ctx.json.scan_details.info.scan_start != '' + formats: + - UNIX + - date: + field: json.scan_details.info.scan_end + target_field: json.scan_details.info.scan_end + if: ctx.json?.scan_details?.info?.scan_end != null && ctx.json.scan_details.info.scan_end != '' + formats: + - UNIX + - date: + field: json.scan_details.info.timestamp + target_field: json.scan_details.info.timestamp + if: ctx.json?.scan_details?.info?.timestamp != null && ctx.json.scan_details.info.timestamp != '' + formats: + - UNIX + - foreach: + field: json.scan_details.history + ignore_missing: true + processor: + date: + field: _ingest._value.creation_date + target_field: _ingest._value.creation_date + formats: + - UNIX + ignore_failure: true + - foreach: + field: json.scan_details.history + ignore_missing: true + processor: + date: + field: _ingest._value.last_modification_date + target_field: _ingest._value.last_modification_date + formats: + - UNIX + ignore_failure: true + - date: + field: json.scan_details.info.scanner_start + target_field: json.scan_details.info.scanner_start + if: ctx.json?.scan_details?.info?.scanner_start != null && ctx.json.scan_details.info.scanner_start != '' formats: - ISO8601 + ignore_failure: true - date: - field: json.scan_details.updated_at - target_field: json.scan_details.updated_at - if: ctx.json?.scan_details?.updated_at != null && ctx.json.scan_details.updated_at != '' + field: json.scan_details.info.scanner_end + target_field: json.scan_details.info.scanner_end + if: ctx.json?.scan_details?.info?.scanner_end != null && ctx.json.scan_details.info.scanner_end != '' formats: - ISO8601 + ignore_failure: true + - remove: + field: json.scan_details.filters + ignore_missing: true - rename: field: json target_field: tenable_io.scan ignore_missing: true + - script: + description: Populate related.ip and related.hosts from scan details. + lang: painless + if: ctx.tenable_io?.scan?.scan_details != null + source: | + def details = ctx.tenable_io.scan.scan_details; + if (ctx.related == null) { ctx.related = new HashMap(); } + if (details.info?.targets != null) { + if (ctx.related.ip == null) { ctx.related.ip = new ArrayList(); } + for (def t : details.info.targets.splitOnToken(',')) { + def ip = t.trim(); + if (ip.length() > 0 && !ctx.related.ip.contains(ip)) { + ctx.related.ip.add(ip); + } + } + } + if (details.hosts instanceof List) { + def ipPat = /^\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}$/; + for (def host : (List) details.hosts) { + if (host?.hostname != null && host.hostname.length() > 0) { + if (ipPat.matcher(host.hostname).matches()) { + if (ctx.related.ip == null) { ctx.related.ip = new ArrayList(); } + if (!ctx.related.ip.contains(host.hostname)) { ctx.related.ip.add(host.hostname); } + } else { + if (ctx.related.hosts == null) { ctx.related.hosts = new ArrayList(); } + if (!ctx.related.hosts.contains(host.hostname)) { ctx.related.hosts.add(host.hostname); } + } + } + } + } - script: description: Drops null/empty values recursively. lang: painless diff --git a/packages/tenable_io/data_stream/scan/fields/fields.yml b/packages/tenable_io/data_stream/scan/fields/fields.yml index ea879a28ba9..4ecf525b212 100644 --- a/packages/tenable_io/data_stream/scan/fields/fields.yml +++ b/packages/tenable_io/data_stream/scan/fields/fields.yml @@ -90,54 +90,385 @@ type: long - name: scan_details type: group - description: Detailed scan information from the WAS v2 scan details API. + description: Detailed scan information from the scan details API (GET /scans/{id}). fields: - - name: scan_id - type: keyword - description: The unique identifier for the scan. - - name: user_id - type: keyword - description: The unique identifier of the user who created the scan. - - name: config_id - type: keyword - description: The unique identifier of the scan configuration. - - name: target - type: keyword - description: The target URL of the scan. - - name: created_at - type: date - description: The date and time when the scan was created. - - name: updated_at - type: date - description: The date and time when the scan was last updated. - - name: requested_action - type: keyword - description: The action requested for the scan (e.g., start, stop). - - name: status - type: keyword - description: The current status of the scan. - - name: metadata + - name: info type: group - description: Metadata about the scan progress and statistics. + description: Top-level metadata about the scan run. fields: - - name: queued_urls + - name: owner + type: keyword + description: The owner of the scan. + - name: name + type: keyword + description: The name of the scan. + - name: no_target + type: boolean + description: Indicates whether the scan based on this policy can specify targets. + - name: folder_id + type: long + description: The unique ID of the destination folder for the scan. + - name: control + type: boolean + description: If true, the scan has a schedule and can be launched. + - name: user_permissions + type: long + description: The sharing permissions for the scan. + - name: schedule_uuid + type: keyword + description: The UUID for a specific instance in the scan schedule. + - name: edit_allowed + type: boolean + description: If true, the requesting user can edit this scan configuration. + - name: scanner_name + type: keyword + description: The name of the scanner configured to run the scan. + - name: policy + type: keyword + description: The name of the scan template associated with the scan. + - name: shared + type: boolean + description: If true, the scan is shared with users other than the owner. + - name: object_id + type: long + description: The unique ID of the scan result object. + - name: tag_targets + type: keyword + description: The list of asset tag UUIDs the scan uses to determine which assets it evaluates. + - name: hostcount + type: long + description: The total number of assets scanned for vulnerabilities. + - name: uuid + type: keyword + description: The UUID of the scan. + - name: status + type: keyword + description: The status of the scan. + - name: scan_type + type: keyword + description: The type of scan (ps, remote, agent, or null). + - name: targets + type: keyword + description: A comma-delimited list of IPv4 addresses configured as targets for the scan. + - name: alt_targets_used + type: boolean + description: If true, Tenable Vulnerability Management did not launch the scan with a target list. + - name: pci-can-upload + type: boolean + description: If true, you can submit the results of the scan for PCI ASV review. + - name: scan_start + type: date + description: The Unix timestamp when the scan run started. + - name: timestamp + type: date + description: The Unix timestamp when the scan run finished. + - name: scan_end + type: date + description: The Unix timestamp when the scan run finished. + - name: is_archived + type: boolean + description: Indicates whether the scan results are older than 35 days. + - name: haskb + type: boolean + description: Indicates whether a scan has a Knowledge Base (KB) associated with it. + - name: hasaudittrail + type: boolean + description: Indicates whether the scan is configured to create an audit trail. + - name: scanner_start + type: date + description: The scan's start time, if the scan is imported. + - name: scanner_end + type: date + description: The scan's end time, if the scan is imported. + - name: acls + type: group + description: An array of objects that control sharing permissions for the scan. + fields: + - name: permissions + type: long + description: The scan permission. + - name: owner + type: long + description: Indicates whether the user or group owns the scan. + - name: display_name + type: keyword + description: The name of the user or group as it appears in the UI. + - name: name + type: keyword + description: The name of the user or group granted the specified permissions. + - name: id + type: long + description: A number representing the display order of the user or group. + - name: type + type: keyword + description: The type of scan permissions (default, user, or group). + - name: hosts + type: group + description: A list of hosts targeted by the scan for the specified run. Absent when info.is_archived is true. + fields: + - name: asset_id + type: long + description: The unique ID of the asset. + - name: host_id + type: long + description: The unique ID of the host. + - name: hostname + type: keyword + description: The name of the host. + - name: host_index + type: long + description: The index for the host. + - name: progress + type: keyword + description: The scan progress of the host. + - name: score type: long - description: The number of URLs queued for scanning. - - name: scan_status + description: The overall score for the host. + - name: severity + type: long + description: The total severity count for the host. + - name: scanprogresscurrent + type: long + description: The current scan progress for the host. + - name: scanprogresstotal + type: long + description: The total scan progress for the host. + - name: numchecksconsidered + type: long + description: The number of checks considered on the host. + - name: totalchecksconsidered + type: long + description: The total number of checks considered on the host. + - name: info + type: long + description: The number of informational findings on the host. + - name: low + type: long + description: The number of low-severity findings on the host. + - name: medium + type: long + description: The number of medium-severity findings on the host. + - name: high + type: long + description: The number of high-severity findings on the host. + - name: critical + type: long + description: The number of critical-severity findings on the host. + - name: severitycount + type: group + description: Severity breakdown for the host. + fields: + - name: item + type: group + description: Array of severity level counts. + fields: + - name: count + type: long + description: The number of findings at this severity level. + - name: severitylevel + type: long + description: The severity level (0=info, 1=low, 2=medium, 3=high, 4=critical). + - name: comphosts + type: group + description: A list of hosts that had compliance checks run against them. Same structure as hosts. Absent when info.is_archived is true. + fields: + - name: asset_id + type: long + description: The unique ID of the asset. + - name: host_id + type: long + description: The unique ID of the host. + - name: hostname + type: keyword + description: The name of the host. + - name: host_index + type: long + description: The index for the host. + - name: progress type: keyword - description: The detailed scan status. - - name: crawled_urls + description: The scan progress of the host. + - name: score + type: long + description: The overall score for the host. + - name: severity + type: long + description: The total severity count for the host. + - name: scanprogresscurrent + type: long + description: The current scan progress for the host. + - name: scanprogresstotal + type: long + description: The total scan progress for the host. + - name: numchecksconsidered + type: long + description: The number of checks considered on the host. + - name: totalchecksconsidered type: long - description: The number of URLs that have been crawled. - - name: queued_pages + description: The total number of checks considered on the host. + - name: info type: long - description: The number of pages queued for auditing. - - name: audited_pages + description: The number of informational findings on the host. + - name: low type: long - description: The number of pages that have been audited. - - name: request_count + description: The number of low-severity findings on the host. + - name: medium type: long - description: The total number of requests made during the scan. - - name: response_time + description: The number of medium-severity findings on the host. + - name: high type: long - description: The average response time in milliseconds. + description: The number of high-severity findings on the host. + - name: critical + type: long + description: The number of critical-severity findings on the host. + - name: severitycount + type: group + description: Severity breakdown for the host. + fields: + - name: item + type: group + description: Array of severity level counts. + fields: + - name: count + type: long + description: The number of findings at this severity level. + - name: severitylevel + type: long + description: The severity level (0=info, 1=low, 2=medium, 3=high, 4=critical). + - name: vulnerabilities + type: group + description: A list of vulnerabilities identified on the target hosts. Absent when info.is_archived is true. + fields: + - name: count + type: long + description: The number of vulnerabilities found. + - name: plugin_id + type: long + description: The unique ID of the vulnerability plugin. + - name: plugin_name + type: keyword + description: The name of the vulnerability plugin. + - name: plugin_family + type: keyword + description: The parent family of the vulnerability plugin. + - name: severity + type: long + description: The severity rating of the plugin. + - name: severity_index + type: long + description: The severity index order of the plugin. + - name: vuln_index + type: long + description: The index of the vulnerability plugin. + - name: compliance + type: group + description: A list of compliance checks performed during the scan run. Absent when info.is_archived is true. + fields: + - name: count + type: long + description: The number of findings. + - name: host_id + type: long + description: The unique ID of the host. + - name: hostname + type: keyword + description: The name of the host. + - name: plugin_family + type: keyword + description: The parent family of the compliance plugin. + - name: plugin_id + type: keyword + description: The unique ID of the compliance plugin (hash string). + - name: plugin_name + type: keyword + description: The name of the compliance plugin. + - name: severity + type: long + description: The severity rating of the plugin. + - name: severity_index + type: long + description: The severity index order of the plugin. + - name: history + type: group + description: A list of details about each time the scan has run. + fields: + - name: history_id + type: long + description: The unique ID of the historical data. + - name: owner_id + type: long + description: The unique ID of the owner of the scan. + - name: uuid + type: keyword + description: The UUID of the historical data. + - name: type + type: keyword + description: The type of scan (local, remote, agent, or null). + - name: status + type: keyword + description: The terminal status of the scan run. + - name: creation_date + type: date + description: The creation date for the historical data in Unix time. + - name: last_modification_date + type: date + description: The last modification date for the historical data in Unix time. + - name: scheduler + type: long + description: If true, Tenable Vulnerability Management launched the scan from a schedule. + - name: alt_targets_used + type: boolean + description: If true, the scan was not launched with a target list. + - name: is_archived + type: boolean + description: Indicates whether the scan results are older than 35 days. + - name: reporting_mode + type: keyword + description: Reporting mode for Nessus Agent scans (baseline, differential, or null). + - name: notes + type: group + description: A list of notes about the scan. + fields: + - name: title + type: keyword + description: The title of the note. + - name: message + type: keyword + description: The specific message of the note. + - name: severity + type: long + description: The severity of the note. + - name: remediations + type: group + description: Remediation summary for the scan. + fields: + - name: num_cves + type: long + description: The number of CVEs addressed by the remediations. + - name: num_hosts + type: long + description: The number of hosts with remediations. + - name: num_remediated_cves + type: long + description: The number of CVEs that have been remediated. + - name: num_impacted_hosts + type: long + description: The number of hosts impacted by the remediations. + - name: remediations + type: group + description: The list of individual remediations. + fields: + - name: vulns + type: long + description: The number of vulnerabilities addressed by this remediation. + - name: value + type: keyword + description: The unique identifier of the remediation. + - name: hosts + type: long + description: The number of hosts affected by this remediation. + - name: remediation + type: keyword + description: A description of the remediation action. + - name: progress + type: long + description: The progress of the scan ranging from 0 to 100. diff --git a/packages/tenable_io/data_stream/scan/sample_event.json b/packages/tenable_io/data_stream/scan/sample_event.json index 3aea534b95f..be7f9d46394 100644 --- a/packages/tenable_io/data_stream/scan/sample_event.json +++ b/packages/tenable_io/data_stream/scan/sample_event.json @@ -1,24 +1,24 @@ { - "@timestamp": "2025-12-03T09:35:39.290Z", + "@timestamp": "2026-07-27T09:30:22.645Z", "agent": { - "ephemeral_id": "6c6451c2-8450-4887-a9dc-d0a16453249c", - "id": "db19321f-465d-4a59-869c-1b771084aa41", - "name": "elastic-agent-46431", + "ephemeral_id": "89c51a06-3c81-4c56-b034-aa89d12c3037", + "id": "7ef6ee8a-3678-479a-b535-b981f847f394", + "name": "elastic-agent-38276", "type": "filebeat", - "version": "9.1.3" + "version": "8.19.0" }, "data_stream": { "dataset": "tenable_io.scan", - "namespace": "47734", + "namespace": "57004", "type": "logs" }, "ecs": { "version": "8.11.0" }, "elastic_agent": { - "id": "db19321f-465d-4a59-869c-1b771084aa41", + "id": "7ef6ee8a-3678-479a-b535-b981f847f394", "snapshot": false, - "version": "9.1.3" + "version": "8.19.0" }, "event": { "agent_id_status": "verified", @@ -26,10 +26,9 @@ "configuration" ], "dataset": "tenable_io.scan", - "ingested": "2025-12-03T09:35:42Z", + "ingested": "2026-07-27T09:30:25Z", "kind": "state", - "module": "tenable_io", - "original": "{\"control\":true,\"creation_date\":1683282785,\"enabled\":true,\"has_triggers\":false,\"id\":195,\"last_modification_date\":1683283158,\"legacy\":false,\"name\":\"Client Discovery\",\"owner\":\"jdoe@contoso.com\",\"permissions\":128,\"policy_id\":194,\"progress\":100,\"read\":false,\"rrules\":\"FREQ=WEEKLY;INTERVAL=1;BYDAY=FR\",\"scan_details\":{\"config_id\":\"a772daba-3d6d-412c-8ee0-3279b19650b2\",\"created_at\":\"2020-02-05T23:11:49.342Z\",\"metadata\":{\"audited_pages\":1,\"crawled_urls\":1,\"queued_pages\":0,\"queued_urls\":0,\"request_count\":74,\"response_time\":0,\"scan_status\":\"stopping\"},\"requested_action\":\"start\",\"scan_id\":\"195\",\"status\":\"completed\",\"target\":\"http://192.0.2.119\",\"updated_at\":\"2020-02-05T23:22:15.510Z\",\"user_id\":\"53e1d711-f18f-4a75-a86e-1c47bccff1b7\"},\"schedule_uuid\":\"11c56dea-as5f-65ce-ad45-9978045df65ecade45b6e3a76871\",\"shared\":true,\"starttime\":\"20220708T033000\",\"status\":\"completed\",\"status_times\":{\"initializing\":2623,\"pending\":52799,\"processing\":1853,\"publishing\":300329,\"running\":15759},\"template_uuid\":\"a1efc3b4-cd45-a65d-fbc4-0079ebef4a56cd32a05ec2812bcf\",\"timezone\":\"America/Los_Angeles\",\"total_targets\":21,\"type\":\"remote\",\"user_permissions\":128,\"uuid\":\"a456ef1c-cbd4-ad41-f654-119b766ff61f\",\"wizard_uuid\":\"32cbd657-fe65-a45e-a45f-0079eb89e56a1c23fd5ec2812bcf\"}", + "original": "{\"control\":true,\"creation_date\":1683282785,\"enabled\":true,\"has_triggers\":false,\"id\":195,\"last_modification_date\":1683283158,\"legacy\":false,\"name\":\"Client Discovery\",\"owner\":\"jdoe@contoso.com\",\"permissions\":128,\"policy_id\":194,\"progress\":100,\"read\":false,\"rrules\":\"FREQ=WEEKLY;INTERVAL=1;BYDAY=FR\",\"scan_details\":{\"history\":[{\"alt_targets_used\":false,\"creation_date\":1683282785,\"history_id\":1000195,\"is_archived\":false,\"last_modification_date\":1683283158,\"owner_id\":1,\"scheduler\":0,\"status\":\"completed\",\"type\":\"remote\",\"uuid\":\"a456ef1c-cbd4-ad41-f654-119b766ff61f\"}],\"hosts\":[{\"asset_id\":5,\"critical\":0,\"high\":3,\"host_id\":5,\"host_index\":0,\"hostname\":\"192.0.2.57\",\"info\":156,\"low\":1,\"medium\":6,\"numchecksconsidered\":100,\"progress\":\"100-100/200-200\",\"scanprogresscurrent\":100,\"scanprogresstotal\":100,\"score\":3766,\"severity\":166,\"severitycount\":{\"item\":[{\"count\":156,\"severitylevel\":0},{\"count\":1,\"severitylevel\":1},{\"count\":6,\"severitylevel\":2},{\"count\":3,\"severitylevel\":3},{\"count\":0,\"severitylevel\":4}]},\"totalchecksconsidered\":100}],\"info\":{\"acls\":[{\"display_name\":\"jdoe@contoso.com\",\"id\":1,\"name\":\"jdoe@contoso.com\",\"owner\":1,\"permissions\":128,\"type\":\"user\"}],\"alt_targets_used\":false,\"control\":true,\"edit_allowed\":true,\"folder_id\":226,\"hasaudittrail\":true,\"haskb\":true,\"hostcount\":1,\"is_archived\":false,\"name\":\"Client Discovery\",\"no_target\":false,\"object_id\":195,\"owner\":\"jdoe@contoso.com\",\"pci-can-upload\":false,\"policy\":null,\"scan_end\":1683283158,\"scan_start\":1683282785,\"scan_type\":\"remote\",\"scanner_end\":null,\"scanner_name\":null,\"scanner_start\":null,\"schedule_uuid\":\"11c56dea-as5f-65ce-ad45-9978045df65ecade45b6e3a76871\",\"shared\":true,\"status\":\"completed\",\"tag_targets\":[],\"targets\":\"192.0.2.57\",\"timestamp\":1683283158,\"user_permissions\":128,\"uuid\":\"a456ef1c-cbd4-ad41-f654-119b766ff61f\"},\"vulnerabilities\":[{\"count\":3,\"plugin_family\":\"Port scanners\",\"plugin_id\":34220,\"plugin_name\":\"Netstat Portscanner (WMI)\",\"severity\":0,\"vuln_index\":1}]},\"schedule_uuid\":\"11c56dea-as5f-65ce-ad45-9978045df65ecade45b6e3a76871\",\"shared\":true,\"starttime\":\"20220708T033000\",\"status\":\"completed\",\"status_times\":{\"initializing\":2623,\"pending\":52799,\"processing\":1853,\"publishing\":300329,\"running\":15759},\"template_uuid\":\"a1efc3b4-cd45-a65d-fbc4-0079ebef4a56cd32a05ec2812bcf\",\"timezone\":\"America/Los_Angeles\",\"total_targets\":21,\"type\":\"remote\",\"user_permissions\":128,\"uuid\":\"a456ef1c-cbd4-ad41-f654-119b766ff61f\",\"wizard_uuid\":\"32cbd657-fe65-a45e-a45f-0079eb89e56a1c23fd5ec2812bcf\"}", "type": [ "info" ] @@ -37,6 +36,11 @@ "input": { "type": "cel" }, + "related": { + "ip": [ + "192.0.2.57" + ] + }, "tags": [ "preserve_original_event", "forwarded", @@ -59,23 +63,109 @@ "read": false, "rrules": "FREQ=WEEKLY;INTERVAL=1;BYDAY=FR", "scan_details": { - "config_id": "a772daba-3d6d-412c-8ee0-3279b19650b2", - "created_at": "2020-02-05T23:11:49.342Z", - "metadata": { - "audited_pages": 1, - "crawled_urls": 1, - "queued_pages": 0, - "queued_urls": 0, - "request_count": 74, - "response_time": 0, - "scan_status": "stopping" + "history": [ + { + "alt_targets_used": false, + "creation_date": "2023-05-05T10:33:05.000Z", + "history_id": 1000195, + "is_archived": false, + "last_modification_date": "2023-05-05T10:39:18.000Z", + "owner_id": 1, + "scheduler": 0, + "status": "completed", + "type": "remote", + "uuid": "a456ef1c-cbd4-ad41-f654-119b766ff61f" + } + ], + "hosts": [ + { + "asset_id": 5, + "critical": 0, + "high": 3, + "host_id": 5, + "host_index": 0, + "hostname": "192.0.2.57", + "info": 156, + "low": 1, + "medium": 6, + "numchecksconsidered": 100, + "progress": "100-100/200-200", + "scanprogresscurrent": 100, + "scanprogresstotal": 100, + "score": 3766, + "severity": 166, + "severitycount": { + "item": [ + { + "count": 156, + "severitylevel": 0 + }, + { + "count": 1, + "severitylevel": 1 + }, + { + "count": 6, + "severitylevel": 2 + }, + { + "count": 3, + "severitylevel": 3 + }, + { + "count": 0, + "severitylevel": 4 + } + ] + }, + "totalchecksconsidered": 100 + } + ], + "info": { + "acls": [ + { + "display_name": "jdoe@contoso.com", + "id": 1, + "name": "jdoe@contoso.com", + "owner": 1, + "permissions": 128, + "type": "user" + } + ], + "alt_targets_used": false, + "control": true, + "edit_allowed": true, + "folder_id": 226, + "hasaudittrail": true, + "haskb": true, + "hostcount": 1, + "is_archived": false, + "name": "Client Discovery", + "no_target": false, + "object_id": 195, + "owner": "jdoe@contoso.com", + "pci-can-upload": false, + "scan_end": "2023-05-05T10:39:18.000Z", + "scan_start": "2023-05-05T10:33:05.000Z", + "scan_type": "remote", + "schedule_uuid": "11c56dea-as5f-65ce-ad45-9978045df65ecade45b6e3a76871", + "shared": true, + "status": "completed", + "targets": "192.0.2.57", + "timestamp": "2023-05-05T10:39:18.000Z", + "user_permissions": 128, + "uuid": "a456ef1c-cbd4-ad41-f654-119b766ff61f" }, - "requested_action": "start", - "scan_id": "195", - "status": "completed", - "target": "http://192.0.2.119", - "updated_at": "2020-02-05T23:22:15.510Z", - "user_id": "53e1d711-f18f-4a75-a86e-1c47bccff1b7" + "vulnerabilities": [ + { + "count": 3, + "plugin_family": "Port scanners", + "plugin_id": 34220, + "plugin_name": "Netstat Portscanner (WMI)", + "severity": 0, + "vuln_index": 1 + } + ] }, "schedule_uuid": "11c56dea-as5f-65ce-ad45-9978045df65ecade45b6e3a76871", "shared": true, diff --git a/packages/tenable_io/data_stream/vulnerability/sample_event.json b/packages/tenable_io/data_stream/vulnerability/sample_event.json index 14a9986533b..5b386ba2366 100644 --- a/packages/tenable_io/data_stream/vulnerability/sample_event.json +++ b/packages/tenable_io/data_stream/vulnerability/sample_event.json @@ -1,22 +1,22 @@ { - "@timestamp": "2018-12-31T20:59:47.000Z", + "@timestamp": "2026-06-27T09:31:14.000Z", "agent": { - "ephemeral_id": "63b3ce92-be95-4199-9b67-c74f08e2c74b", - "id": "7e8cf2c9-64ff-4492-9ac5-4e1891bf1ba8", - "name": "elastic-agent-91222", + "ephemeral_id": "1545d2cd-cc2d-4820-bf30-8edcf93816a5", + "id": "486e15a6-87d8-48ea-9a11-3d8c82352a4a", + "name": "elastic-agent-11613", "type": "filebeat", "version": "8.19.0" }, "data_stream": { "dataset": "tenable_io.vulnerability", - "namespace": "65767", + "namespace": "94687", "type": "logs" }, "ecs": { "version": "8.11.0" }, "elastic_agent": { - "id": "7e8cf2c9-64ff-4492-9ac5-4e1891bf1ba8", + "id": "486e15a6-87d8-48ea-9a11-3d8c82352a4a", "snapshot": false, "version": "8.19.0" }, @@ -25,11 +25,11 @@ "category": [ "vulnerability" ], - "created": "2022-11-30T14:09:12.061Z", + "created": "2026-06-28T09:31:14.000Z", "dataset": "tenable_io.vulnerability", - "ingested": "2025-09-19T09:10:30Z", + "ingested": "2026-07-27T09:31:17Z", "kind": "state", - "original": "{\"asset\":{\"fqdn\":\"example.com\",\"hostname\":\"89.160.20.112\",\"ipv4\":\"81.2.69.142\",\"network_id\":\"00000000-0000-0000-0000-000000000000\",\"operating_system\":[\"Test Demo OS X 10.5.8\"],\"tracked\":true,\"uuid\":\"cf165808-6a31-48e1-9cf3-c6c3174df51d\"},\"first_found\":\"2018-12-31T20:59:47Z\",\"indexed\":\"2022-11-30T14:09:12.061Z\",\"last_found\":\"2018-12-31T20:59:47Z\",\"output\":\"\\n Path : /opt/jdk-11.0.2/\\n Installed version : 11.0.2\\n Fixed version : Upgrade to a version greater than 11.0.18\\n\\n\\n\\n Path : /usr/java/jdk1.8.0_232-cloudera/\\n Installed version : 8.0.232\\n Fixed version : Upgrade to a version greater than 8u362\\n\",\"plugin\":{\"cve\":[\"CVE-2016-1620\",\"CVE-2016-1614\",\"CVE-2016-1613\",\"CVE-2016-1612\",\"CVE-2016-1618\",\"CVE-2016-1617\",\"CVE-2016-1616\",\"CVE-2016-1615\",\"CVE-2016-1619\"],\"cvss_base_score\":9.3,\"cvss_temporal_score\":6.9,\"cvss_temporal_vector\":{\"exploitability\":\"Unproven\",\"raw\":\"E:U/RL:OF/RC:C\",\"remediation_level\":\"Official-fix\",\"report_confidence\":\"Confirmed\"},\"cvss_vector\":{\"access_complexity\":\"Medium\",\"access_vector\":\"Network\",\"authentication\":\"None required\",\"availability_impact\":\"Complete\",\"confidentiality_impact\":\"Complete\",\"integrity_impact\":\"Complete\",\"raw\":\"AV:N/AC:M/Au:N/C:C/I:C/A:C\"},\"description\":\"The version of Test on the remote host is prior to 48.0.2564.82 and is affected by the following vulnerabilities: \\n\\n - An unspecified vulnerability exists in Test V8 when handling compatible receiver checks hidden behind receptors. An attacker can exploit this to have an unspecified impact. No other details are available. (CVE-2016-1612)\\n - A use-after-free error exists in `PDFium` due to improper invalidation of `IPWL_FocusHandler` and `IPWL_Provider` upon destruction. An attacker can exploit this to dereference already freed memory, resulting in the execution of arbitrary code. (CVE-2016-1613)\\n - An unspecified vulnerability exists in `Blink` that is related to the handling of bitmaps. An attacker can exploit this to access sensitive information. No other details are available. (CVE-2016-1614)\\n - An unspecified vulnerability exists in `omnibox` that is related to origin confusion. An attacker can exploit this to have an unspecified impact. No other details are available. (CVE-2016-1615)\\n - An unspecified vulnerability exists that allows an attacker to spoof a displayed URL. No other details are available. (CVE-2016-1616)\\n - An unspecified vulnerability exists that is related to history sniffing with HSTS and CSP. No other details are available. (CVE-2016-1617)\\n - A flaw exists in `Blink` due to the weak generation of random numbers by the ARC4-based random number generator. An attacker can exploit this to gain access to sensitive information. No other details are available. (CVE-2016-1618)\\n - An out-of-bounds read error exists in `PDFium` in file `fx_codec_jpx_opj.cpp` in the `sycc4{22,44}_to_rgb()` functions. An attacker can exploit this to cause a denial of service by crashing the application linked using the library. (CVE-2016-1619)\\n - Multiple vulnerabilities exist, the most serious of which allow an attacker to execute arbitrary code via a crafted web page. (CVE-2016-1620)\\n - A flaw in `objects.cc` is triggered when handling cleared `WeakCells`, which may allow a context-dependent attacker to have an unspecified impact. No further details have been provided. (CVE-2016-2051)\",\"family\":\"Web Clients\",\"family_id\":1000020,\"has_patch\":false,\"id\":9062,\"name\":\"Test \\u0026lt; 48.0.2564.82 Multiple Vulnerabilities\",\"risk_factor\":\"HIGH\",\"see_also\":[\"http://testreleases.blogspot.com/2016/01/beta-channel-update_20.html\"],\"solution\":\"Update the browser to 48.0.2564.82 or later.\",\"synopsis\":\"The remote host is utilizing a web browser that is affected by multiple vulnerabilities.\",\"vpr\":{\"drivers\":{\"age_of_vuln\":{\"lower_bound\":366,\"upper_bound\":730},\"cvss3_impact_score\":5.9,\"cvss_impact_score_predicted\":false,\"exploit_code_maturity\":\"UNPROVEN\",\"product_coverage\":\"LOW\",\"threat_intensity_last28\":\"VERY_LOW\",\"threat_sources_last28\":[\"No recorded events\"]},\"score\":5.9,\"updated\":\"2019-12-31T10:08:58Z\"},\"vuln_publication_date\":\"2023-04-18T00:00:00Z\"},\"port\":{\"port\":\"0\",\"protocol\":\"TCP\"},\"scan\":{\"completed_at\":\"2018-12-31T20:59:47Z\",\"schedule_uuid\":\"6f7db010-9cb6-4870-b745-70a2aea2f81ce1b6640fe8a2217b\",\"started_at\":\"2018-12-31T20:59:47Z\",\"uuid\":\"0e55ec5d-c7c7-4673-a618-438a84e9d1b78af3a9957a077904\"},\"severity\":\"low\",\"severity_default_id\":3,\"severity_id\":3,\"severity_modification_type\":\"NONE\",\"state\":\"OPEN\"}", + "original": "{\"asset\":{\"fqdn\":\"example.com\",\"hostname\":\"89.160.20.112\",\"ipv4\":\"81.2.69.142\",\"network_id\":\"00000000-0000-0000-0000-000000000000\",\"operating_system\":[\"Test Demo OS X 10.5.8\"],\"tracked\":true,\"uuid\":\"cf165808-6a31-48e1-9cf3-c6c3174df51d\"},\"first_found\":\"2026-06-27T09:31:14Z\",\"indexed\":\"2026-06-28T09:31:14Z\",\"last_found\":\"2026-06-27T09:31:14Z\",\"output\":\"\\n Path : /opt/jdk-11.0.2/\\n Installed version : 11.0.2\\n Fixed version : Upgrade to a version greater than 11.0.18\\n\\n\\n\\n Path : /usr/java/jdk1.8.0_232-cloudera/\\n Installed version : 8.0.232\\n Fixed version : Upgrade to a version greater than 8u362\\n\",\"plugin\":{\"cve\":[\"CVE-2016-1620\",\"CVE-2016-1614\",\"CVE-2016-1613\",\"CVE-2016-1612\",\"CVE-2016-1618\",\"CVE-2016-1617\",\"CVE-2016-1616\",\"CVE-2016-1615\",\"CVE-2016-1619\"],\"cvss_base_score\":9.3,\"cvss_temporal_score\":6.9,\"cvss_temporal_vector\":{\"exploitability\":\"Unproven\",\"raw\":\"E:U/RL:OF/RC:C\",\"remediation_level\":\"Official-fix\",\"report_confidence\":\"Confirmed\"},\"cvss_vector\":{\"access_complexity\":\"Medium\",\"access_vector\":\"Network\",\"authentication\":\"None required\",\"availability_impact\":\"Complete\",\"confidentiality_impact\":\"Complete\",\"integrity_impact\":\"Complete\",\"raw\":\"AV:N/AC:M/Au:N/C:C/I:C/A:C\"},\"description\":\"The version of Test on the remote host is prior to 48.0.2564.82 and is affected by the following vulnerabilities: \\n\\n - An unspecified vulnerability exists in Test V8 when handling compatible receiver checks hidden behind receptors. An attacker can exploit this to have an unspecified impact. No other details are available. (CVE-2016-1612)\\n - A use-after-free error exists in `PDFium` due to improper invalidation of `IPWL_FocusHandler` and `IPWL_Provider` upon destruction. An attacker can exploit this to dereference already freed memory, resulting in the execution of arbitrary code. (CVE-2016-1613)\\n - An unspecified vulnerability exists in `Blink` that is related to the handling of bitmaps. An attacker can exploit this to access sensitive information. No other details are available. (CVE-2016-1614)\\n - An unspecified vulnerability exists in `omnibox` that is related to origin confusion. An attacker can exploit this to have an unspecified impact. No other details are available. (CVE-2016-1615)\\n - An unspecified vulnerability exists that allows an attacker to spoof a displayed URL. No other details are available. (CVE-2016-1616)\\n - An unspecified vulnerability exists that is related to history sniffing with HSTS and CSP. No other details are available. (CVE-2016-1617)\\n - A flaw exists in `Blink` due to the weak generation of random numbers by the ARC4-based random number generator. An attacker can exploit this to gain access to sensitive information. No other details are available. (CVE-2016-1618)\\n - An out-of-bounds read error exists in `PDFium` in file `fx_codec_jpx_opj.cpp` in the `sycc4{22,44}_to_rgb()` functions. An attacker can exploit this to cause a denial of service by crashing the application linked using the library. (CVE-2016-1619)\\n - Multiple vulnerabilities exist, the most serious of which allow an attacker to execute arbitrary code via a crafted web page. (CVE-2016-1620)\\n - A flaw in `objects.cc` is triggered when handling cleared `WeakCells`, which may allow a context-dependent attacker to have an unspecified impact. No further details have been provided. (CVE-2016-2051)\",\"family\":\"Web Clients\",\"family_id\":1000020,\"has_patch\":false,\"id\":9062,\"name\":\"Test \\u0026lt; 48.0.2564.82 Multiple Vulnerabilities\",\"risk_factor\":\"HIGH\",\"see_also\":[\"http://testreleases.blogspot.com/2016/01/beta-channel-update_20.html\"],\"solution\":\"Update the browser to 48.0.2564.82 or later.\",\"synopsis\":\"The remote host is utilizing a web browser that is affected by multiple vulnerabilities.\",\"vpr\":{\"drivers\":{\"age_of_vuln\":{\"lower_bound\":366,\"upper_bound\":730},\"cvss3_impact_score\":5.9,\"cvss_impact_score_predicted\":false,\"exploit_code_maturity\":\"UNPROVEN\",\"product_coverage\":\"LOW\",\"threat_intensity_last28\":\"VERY_LOW\",\"threat_sources_last28\":[\"No recorded events\"]},\"score\":5.9,\"updated\":\"2019-12-31T10:08:58Z\"},\"vuln_publication_date\":\"2023-04-18T00:00:00Z\"},\"port\":{\"port\":\"0\",\"protocol\":\"TCP\"},\"scan\":{\"completed_at\":\"2018-12-31T20:59:47Z\",\"schedule_uuid\":\"6f7db010-9cb6-4870-b745-70a2aea2f81ce1b6640fe8a2217b\",\"started_at\":\"2018-12-31T20:59:47Z\",\"uuid\":\"0e55ec5d-c7c7-4673-a618-438a84e9d1b78af3a9957a077904\"},\"severity\":\"low\",\"severity_default_id\":3,\"severity_id\":3,\"severity_modification_type\":\"NONE\",\"state\":\"OPEN\"}", "type": [ "info" ] @@ -104,9 +104,9 @@ "tracked": true, "uuid": "cf165808-6a31-48e1-9cf3-c6c3174df51d" }, - "first_found": "2018-12-31T20:59:47.000Z", - "indexed": "2022-11-30T14:09:12.061Z", - "last_found": "2018-12-31T20:59:47.000Z", + "first_found": "2026-06-27T09:31:14.000Z", + "indexed": "2026-06-28T09:31:14.000Z", + "last_found": "2026-06-27T09:31:14.000Z", "output": "\n Path : /opt/jdk-11.0.2/\n Installed version : 11.0.2\n Fixed version : Upgrade to a version greater than 11.0.18\n\n\n\n Path : /usr/java/jdk1.8.0_232-cloudera/\n Installed version : 8.0.232\n Fixed version : Upgrade to a version greater than 8u362\n", "package_nested": [ { diff --git a/packages/tenable_io/docs/README.md b/packages/tenable_io/docs/README.md index a46c5925a1b..181e5b009f5 100644 --- a/packages/tenable_io/docs/README.md +++ b/packages/tenable_io/docs/README.md @@ -18,7 +18,7 @@ The Tenable Vulnerability Management integration collects logs for five types of **Vulnerability** is used to retrieve all vulnerabilities on each asset, including the vulnerability state. See more details in the API documentation [here](https://developer.tenable.com/reference/exports-vulns-request-export). -**Scan** is used to retrieve details about existing scans and scan details, including scan statuses, assigned targets, and more. See more details in the API documentation for [Scan](https://developer.tenable.com/reference/scans-list) and [Scan Details](https://developer.tenable.com/reference/was-v2-scans-details). +**Scan** is used to retrieve details about existing scans and scan details, including scan statuses, assigned targets, and more. See more details in the API documentation for [Scan](https://developer.tenable.com/reference/scans-list) and [Scan Details](https://developer.tenable.com/reference/scans-details). ## Compatibility @@ -95,11 +95,11 @@ An example event for `asset` looks as following: { "@timestamp": "2018-12-31T22:27:58.599Z", "agent": { - "ephemeral_id": "f945f2c2-fbaf-4b93-b6ca-7d51e6a0706d", - "id": "a0570906-16fc-4c38-821f-7c3aa6ed04bb", - "name": "docker-fleet-agent", + "ephemeral_id": "d1524bb7-93f3-43e5-a4e8-691b38ada6fc", + "id": "42f9eef6-3014-478c-b828-bbcbda65cf4f", + "name": "elastic-agent-15508", "type": "filebeat", - "version": "8.12.0" + "version": "8.19.0" }, "cloud": { "availability_zone": "12", @@ -112,16 +112,16 @@ An example event for `asset` looks as following: }, "data_stream": { "dataset": "tenable_io.asset", - "namespace": "ep", + "namespace": "54262", "type": "logs" }, "ecs": { "version": "8.11.0" }, "elastic_agent": { - "id": "a0570906-16fc-4c38-821f-7c3aa6ed04bb", + "id": "42f9eef6-3014-478c-b828-bbcbda65cf4f", "snapshot": false, - "version": "8.12.0" + "version": "8.19.0" }, "event": { "agent_id_status": "verified", @@ -129,7 +129,7 @@ An example event for `asset` looks as following: "host" ], "dataset": "tenable_io.asset", - "ingested": "2024-04-02T09:13:00Z", + "ingested": "2026-07-27T09:27:59Z", "kind": "state", "original": "{\"acr_score\":\"3\",\"agent_names\":[],\"agent_uuid\":\"22\",\"aws_availability_zone\":null,\"aws_ec2_instance_ami_id\":\"12\",\"aws_ec2_instance_group_name\":null,\"aws_ec2_instance_id\":\"12\",\"aws_ec2_instance_state_name\":null,\"aws_ec2_instance_type\":null,\"aws_ec2_name\":null,\"aws_ec2_product_code\":null,\"aws_owner_id\":\"44\",\"aws_region\":null,\"aws_subnet_id\":null,\"aws_vpc_id\":null,\"azure_resource_id\":\"12\",\"azure_vm_id\":\"12\",\"bigfix_asset_id\":null,\"bios_uuid\":\"33\",\"created_at\":\"2017-12-31T20:40:44.535Z\",\"deleted_at\":\"2017-12-31T20:40:44.535Z\",\"deleted_by\":\"user\",\"exposure_score\":\"721\",\"first_scan_time\":\"2017-12-31T20:40:23.447Z\",\"first_seen\":\"2017-12-31T20:40:23.447Z\",\"fqdns\":[\"example.com\"],\"gcp_instance_id\":\"12\",\"gcp_project_id\":\"12\",\"gcp_zone\":\"12\",\"has_agent\":false,\"has_plugin_results\":true,\"hostnames\":[],\"id\":\"95c2725c-7298-4a44-8a1d-63131ca3f01f\",\"installed_software\":[\"cpe:/a:test:xyz:12.8\",\"cpe:/a:test:abc:7.7.3\",\"cpe:/a:test:pqr:6.9\",\"cpe:/a:test:xyz\"],\"ipv4s\":[\"89.160.20.112\"],\"ipv6s\":[],\"last_authenticated_scan_date\":\"2017-12-31T20:40:44.535Z\",\"last_licensed_scan_date\":\"2018-12-31T22:27:52.869Z\",\"last_scan_id\":\"00283024-afee-44ea-b467-db5a6ed9fd50ab8f7ecb158c480e\",\"last_scan_time\":\"2018-03-31T22:27:52.869Z\",\"last_schedule_id\":\"72284901-7c68-42b2-a0c4-c1e75568849df60557ee0e264228\",\"last_seen\":\"2018-12-31T22:27:52.869Z\",\"mac_addresses\":[],\"manufacturer_tpm_ids\":[],\"mcafee_epo_agent_guid\":null,\"mcafee_epo_guid\":null,\"netbios_names\":[],\"network_interfaces\":[{\"fqdns\":[\"example.com\"],\"ipv4s\":[\"89.160.20.112\",\"81.2.69.144\"],\"ipv6s\":[\"2a02:cf40::\"],\"mac_addresses\":[\"00-00-5E-00-53-00\",\"00-00-5E-00-53-FF\"],\"name\":\"test.0.1234\"}],\"operating_systems\":[],\"qualys_asset_ids\":[],\"qualys_host_ids\":[],\"servicenow_sysid\":null,\"sources\":[{\"first_seen\":\"2017-12-31T20:40:23.447Z\",\"last_seen\":\"2018-12-31T22:27:52.869Z\",\"name\":\"TEST_SCAN\"}],\"ssh_fingerprints\":[],\"symantec_ep_hardware_keys\":[],\"system_types\":[],\"tags\":[{\"added_at\":\"2018-12-31T14:53:13.817Z\",\"added_by\":\"ac2e7ef6-fac9-47bf-9170-617331322885\",\"key\":\"Geographic Area\",\"uuid\":\"47e7f5f6-1013-4401-a705-479bfadc7826\",\"value\":\"APAC\"}],\"terminated_at\":\"2017-12-31T20:40:44.535Z\",\"terminated_by\":\"user\",\"updated_at\":\"2018-12-31T22:27:58.599Z\"}", "type": [ @@ -366,24 +366,24 @@ An example event for `audit` looks as following: { "@timestamp": "2018-12-31T01:40:07.000Z", "agent": { - "ephemeral_id": "2b353f6e-e21d-4e61-a426-9b582471c1fa", - "id": "1a70a431-df2f-4f16-9352-a30f75fb1df2", - "name": "elastic-agent-83695", + "ephemeral_id": "48852dc2-5fcd-43e2-9dcf-91f496198616", + "id": "54bb10de-7dac-4d6f-8f76-b0fa753a6755", + "name": "elastic-agent-12062", "type": "filebeat", - "version": "8.18.1" + "version": "8.19.0" }, "data_stream": { "dataset": "tenable_io.audit", - "namespace": "31446", + "namespace": "73649", "type": "logs" }, "ecs": { "version": "8.11.0" }, "elastic_agent": { - "id": "1a70a431-df2f-4f16-9352-a30f75fb1df2", + "id": "54bb10de-7dac-4d6f-8f76-b0fa753a6755", "snapshot": false, - "version": "8.18.1" + "version": "8.19.0" }, "event": { "action": "session-delete", @@ -393,7 +393,7 @@ An example event for `audit` looks as following: ], "dataset": "tenable_io.audit", "id": "eaac53481de04f67bc7eeea07d2fb0f5", - "ingested": "2025-06-03T16:34:47Z", + "ingested": "2026-07-27T09:28:46Z", "kind": "event", "original": "{\"action\":\"session.delete\",\"actor\":{\"id\":\"d2667922-5a27-4c4a-9207-f591fbdc9d23\",\"name\":\"user2@example.com\"},\"crud\":\"d\",\"description\":null,\"fields\":[{\"key\":\"message\",\"value\":\"session timeout\"}],\"id\":\"eaac53481de04f67bc7eeea07d2fb0f5\",\"is_anonymous\":null,\"is_failure\":false,\"received\":\"2018-12-31T01:40:07Z\",\"target\":{\"id\":\"12d024e\",\"name\":null,\"type\":\"Session\"}}", "outcome": "success", @@ -485,29 +485,29 @@ An example event for `plugin` looks as following: { "@timestamp": "2018-07-19T00:00:00.000Z", "agent": { - "ephemeral_id": "f945f2c2-fbaf-4b93-b6ca-7d51e6a0706d", - "id": "a0570906-16fc-4c38-821f-7c3aa6ed04bb", - "name": "docker-fleet-agent", + "ephemeral_id": "30513499-3121-45dd-8e75-67e3b042d3a1", + "id": "1fa7cf0a-419d-4967-a86b-696c132d365d", + "name": "elastic-agent-96491", "type": "filebeat", - "version": "8.12.0" + "version": "8.19.0" }, "data_stream": { "dataset": "tenable_io.plugin", - "namespace": "ep", + "namespace": "72547", "type": "logs" }, "ecs": { "version": "8.11.0" }, "elastic_agent": { - "id": "a0570906-16fc-4c38-821f-7c3aa6ed04bb", + "id": "1fa7cf0a-419d-4967-a86b-696c132d365d", "snapshot": false, - "version": "8.12.0" + "version": "8.19.0" }, "event": { "agent_id_status": "verified", "dataset": "tenable_io.plugin", - "ingested": "2024-04-02T09:13:52Z", + "ingested": "2026-07-27T09:29:35Z", "kind": "state", "original": "{\"attributes\":{\"cpe\":[\"p-cpe:/a:fedoraproject:fedora:kernel-source\",\"cpe:/o:fedoraproject:fedora_core:1\",\"p-cpe:/a:fedoraproject:fedora:kernel-BOOT\",\"p-cpe:/a:fedoraproject:fedora:kernel-debuginfo\",\"p-cpe:/a:fedoraproject:fedora:kernel\",\"p-cpe:/a:fedoraproject:fedora:kernel-doc\",\"p-cpe:/a:fedoraproject:fedora:kernel-smp\"],\"cve\":[\"CVE-2003-0984\"],\"cvss3_base_score\":0,\"cvss3_temporal_score\":0,\"cvss_base_score\":4.6,\"cvss_temporal_score\":0,\"cvss_vector\":{\"AccessComplexity\":\"Low\",\"AccessVector\":\"Local-access\",\"Authentication\":\"None required\",\"Availability-Impact\":\"Partial\",\"Confidentiality-Impact\":\"Partial\",\"Integrity-Impact\":\"Partial\",\"raw\":\"AV:L/AC:L/Au:N/C:P/I:P/A:P\"},\"default_account\":false,\"description\":\"Various RTC drivers had the potential to leak...\",\"exploit_available\":false,\"exploit_framework_canvas\":false,\"exploit_framework_core\":false,\"exploit_framework_d2_elliot\":false,\"exploit_framework_exploithub\":false,\"exploit_framework_metasploit\":false,\"exploited_by_malware\":false,\"exploited_by_nessus\":false,\"has_patch\":true,\"in_the_news\":false,\"malware\":false,\"patch_publication_date\":\"2004-01-07T00:00:00Z\",\"plugin_modification_date\":\"2018-07-19T00:00:00Z\",\"plugin_publication_date\":\"2004-07-23T00:00:00Z\",\"plugin_type\":\"local\",\"plugin_version\":\"1.17\",\"risk_factor\":\"Medium\",\"see_also\":[\"http://example.com/u?07bc9e7f\"],\"solution\":\"Update the affected packages.\",\"synopsis\":\"The remote Fedora Core host is missing a security update.\",\"unsupported_by_vendor\":false,\"vpr\":{\"drivers\":{\"age_of_vuln\":{\"lower_bound\":366,\"upper_bound\":730},\"cvss3_impact_score\":5.9,\"cvss_impact_score_predicted\":false,\"exploit_code_maturity\":\"UNPROVEN\",\"product_coverage\":\"LOW\",\"threat_intensity_last28\":\"VERY_LOW\",\"threat_recency\":{\"lower_bound\":366,\"upper_bound\":730},\"threat_sources_last28\":[\"No recorded events\"]},\"score\":5.5,\"updated\":\"2018-07-19T00:00:00Z\"},\"xref\":[\"FEDORA:2003-047\"],\"xrefs\":[{\"id\":\"2003-047\",\"type\":\"FEDORA\"}]},\"id\":13670,\"name\":\"Fedora Core 1 : kernel-2.4.22-1.2140.nptl (2003-047)\"}", "type": [ @@ -749,24 +749,24 @@ An example event for `vulnerability` looks as following: ```json { - "@timestamp": "2018-12-31T20:59:47.000Z", + "@timestamp": "2026-06-27T09:31:14.000Z", "agent": { - "ephemeral_id": "63b3ce92-be95-4199-9b67-c74f08e2c74b", - "id": "7e8cf2c9-64ff-4492-9ac5-4e1891bf1ba8", - "name": "elastic-agent-91222", + "ephemeral_id": "1545d2cd-cc2d-4820-bf30-8edcf93816a5", + "id": "486e15a6-87d8-48ea-9a11-3d8c82352a4a", + "name": "elastic-agent-11613", "type": "filebeat", "version": "8.19.0" }, "data_stream": { "dataset": "tenable_io.vulnerability", - "namespace": "65767", + "namespace": "94687", "type": "logs" }, "ecs": { "version": "8.11.0" }, "elastic_agent": { - "id": "7e8cf2c9-64ff-4492-9ac5-4e1891bf1ba8", + "id": "486e15a6-87d8-48ea-9a11-3d8c82352a4a", "snapshot": false, "version": "8.19.0" }, @@ -775,11 +775,11 @@ An example event for `vulnerability` looks as following: "category": [ "vulnerability" ], - "created": "2022-11-30T14:09:12.061Z", + "created": "2026-06-28T09:31:14.000Z", "dataset": "tenable_io.vulnerability", - "ingested": "2025-09-19T09:10:30Z", + "ingested": "2026-07-27T09:31:17Z", "kind": "state", - "original": "{\"asset\":{\"fqdn\":\"example.com\",\"hostname\":\"89.160.20.112\",\"ipv4\":\"81.2.69.142\",\"network_id\":\"00000000-0000-0000-0000-000000000000\",\"operating_system\":[\"Test Demo OS X 10.5.8\"],\"tracked\":true,\"uuid\":\"cf165808-6a31-48e1-9cf3-c6c3174df51d\"},\"first_found\":\"2018-12-31T20:59:47Z\",\"indexed\":\"2022-11-30T14:09:12.061Z\",\"last_found\":\"2018-12-31T20:59:47Z\",\"output\":\"\\n Path : /opt/jdk-11.0.2/\\n Installed version : 11.0.2\\n Fixed version : Upgrade to a version greater than 11.0.18\\n\\n\\n\\n Path : /usr/java/jdk1.8.0_232-cloudera/\\n Installed version : 8.0.232\\n Fixed version : Upgrade to a version greater than 8u362\\n\",\"plugin\":{\"cve\":[\"CVE-2016-1620\",\"CVE-2016-1614\",\"CVE-2016-1613\",\"CVE-2016-1612\",\"CVE-2016-1618\",\"CVE-2016-1617\",\"CVE-2016-1616\",\"CVE-2016-1615\",\"CVE-2016-1619\"],\"cvss_base_score\":9.3,\"cvss_temporal_score\":6.9,\"cvss_temporal_vector\":{\"exploitability\":\"Unproven\",\"raw\":\"E:U/RL:OF/RC:C\",\"remediation_level\":\"Official-fix\",\"report_confidence\":\"Confirmed\"},\"cvss_vector\":{\"access_complexity\":\"Medium\",\"access_vector\":\"Network\",\"authentication\":\"None required\",\"availability_impact\":\"Complete\",\"confidentiality_impact\":\"Complete\",\"integrity_impact\":\"Complete\",\"raw\":\"AV:N/AC:M/Au:N/C:C/I:C/A:C\"},\"description\":\"The version of Test on the remote host is prior to 48.0.2564.82 and is affected by the following vulnerabilities: \\n\\n - An unspecified vulnerability exists in Test V8 when handling compatible receiver checks hidden behind receptors. An attacker can exploit this to have an unspecified impact. No other details are available. (CVE-2016-1612)\\n - A use-after-free error exists in `PDFium` due to improper invalidation of `IPWL_FocusHandler` and `IPWL_Provider` upon destruction. An attacker can exploit this to dereference already freed memory, resulting in the execution of arbitrary code. (CVE-2016-1613)\\n - An unspecified vulnerability exists in `Blink` that is related to the handling of bitmaps. An attacker can exploit this to access sensitive information. No other details are available. (CVE-2016-1614)\\n - An unspecified vulnerability exists in `omnibox` that is related to origin confusion. An attacker can exploit this to have an unspecified impact. No other details are available. (CVE-2016-1615)\\n - An unspecified vulnerability exists that allows an attacker to spoof a displayed URL. No other details are available. (CVE-2016-1616)\\n - An unspecified vulnerability exists that is related to history sniffing with HSTS and CSP. No other details are available. (CVE-2016-1617)\\n - A flaw exists in `Blink` due to the weak generation of random numbers by the ARC4-based random number generator. An attacker can exploit this to gain access to sensitive information. No other details are available. (CVE-2016-1618)\\n - An out-of-bounds read error exists in `PDFium` in file `fx_codec_jpx_opj.cpp` in the `sycc4{22,44}_to_rgb()` functions. An attacker can exploit this to cause a denial of service by crashing the application linked using the library. (CVE-2016-1619)\\n - Multiple vulnerabilities exist, the most serious of which allow an attacker to execute arbitrary code via a crafted web page. (CVE-2016-1620)\\n - A flaw in `objects.cc` is triggered when handling cleared `WeakCells`, which may allow a context-dependent attacker to have an unspecified impact. No further details have been provided. (CVE-2016-2051)\",\"family\":\"Web Clients\",\"family_id\":1000020,\"has_patch\":false,\"id\":9062,\"name\":\"Test \\u0026lt; 48.0.2564.82 Multiple Vulnerabilities\",\"risk_factor\":\"HIGH\",\"see_also\":[\"http://testreleases.blogspot.com/2016/01/beta-channel-update_20.html\"],\"solution\":\"Update the browser to 48.0.2564.82 or later.\",\"synopsis\":\"The remote host is utilizing a web browser that is affected by multiple vulnerabilities.\",\"vpr\":{\"drivers\":{\"age_of_vuln\":{\"lower_bound\":366,\"upper_bound\":730},\"cvss3_impact_score\":5.9,\"cvss_impact_score_predicted\":false,\"exploit_code_maturity\":\"UNPROVEN\",\"product_coverage\":\"LOW\",\"threat_intensity_last28\":\"VERY_LOW\",\"threat_sources_last28\":[\"No recorded events\"]},\"score\":5.9,\"updated\":\"2019-12-31T10:08:58Z\"},\"vuln_publication_date\":\"2023-04-18T00:00:00Z\"},\"port\":{\"port\":\"0\",\"protocol\":\"TCP\"},\"scan\":{\"completed_at\":\"2018-12-31T20:59:47Z\",\"schedule_uuid\":\"6f7db010-9cb6-4870-b745-70a2aea2f81ce1b6640fe8a2217b\",\"started_at\":\"2018-12-31T20:59:47Z\",\"uuid\":\"0e55ec5d-c7c7-4673-a618-438a84e9d1b78af3a9957a077904\"},\"severity\":\"low\",\"severity_default_id\":3,\"severity_id\":3,\"severity_modification_type\":\"NONE\",\"state\":\"OPEN\"}", + "original": "{\"asset\":{\"fqdn\":\"example.com\",\"hostname\":\"89.160.20.112\",\"ipv4\":\"81.2.69.142\",\"network_id\":\"00000000-0000-0000-0000-000000000000\",\"operating_system\":[\"Test Demo OS X 10.5.8\"],\"tracked\":true,\"uuid\":\"cf165808-6a31-48e1-9cf3-c6c3174df51d\"},\"first_found\":\"2026-06-27T09:31:14Z\",\"indexed\":\"2026-06-28T09:31:14Z\",\"last_found\":\"2026-06-27T09:31:14Z\",\"output\":\"\\n Path : /opt/jdk-11.0.2/\\n Installed version : 11.0.2\\n Fixed version : Upgrade to a version greater than 11.0.18\\n\\n\\n\\n Path : /usr/java/jdk1.8.0_232-cloudera/\\n Installed version : 8.0.232\\n Fixed version : Upgrade to a version greater than 8u362\\n\",\"plugin\":{\"cve\":[\"CVE-2016-1620\",\"CVE-2016-1614\",\"CVE-2016-1613\",\"CVE-2016-1612\",\"CVE-2016-1618\",\"CVE-2016-1617\",\"CVE-2016-1616\",\"CVE-2016-1615\",\"CVE-2016-1619\"],\"cvss_base_score\":9.3,\"cvss_temporal_score\":6.9,\"cvss_temporal_vector\":{\"exploitability\":\"Unproven\",\"raw\":\"E:U/RL:OF/RC:C\",\"remediation_level\":\"Official-fix\",\"report_confidence\":\"Confirmed\"},\"cvss_vector\":{\"access_complexity\":\"Medium\",\"access_vector\":\"Network\",\"authentication\":\"None required\",\"availability_impact\":\"Complete\",\"confidentiality_impact\":\"Complete\",\"integrity_impact\":\"Complete\",\"raw\":\"AV:N/AC:M/Au:N/C:C/I:C/A:C\"},\"description\":\"The version of Test on the remote host is prior to 48.0.2564.82 and is affected by the following vulnerabilities: \\n\\n - An unspecified vulnerability exists in Test V8 when handling compatible receiver checks hidden behind receptors. An attacker can exploit this to have an unspecified impact. No other details are available. (CVE-2016-1612)\\n - A use-after-free error exists in `PDFium` due to improper invalidation of `IPWL_FocusHandler` and `IPWL_Provider` upon destruction. An attacker can exploit this to dereference already freed memory, resulting in the execution of arbitrary code. (CVE-2016-1613)\\n - An unspecified vulnerability exists in `Blink` that is related to the handling of bitmaps. An attacker can exploit this to access sensitive information. No other details are available. (CVE-2016-1614)\\n - An unspecified vulnerability exists in `omnibox` that is related to origin confusion. An attacker can exploit this to have an unspecified impact. No other details are available. (CVE-2016-1615)\\n - An unspecified vulnerability exists that allows an attacker to spoof a displayed URL. No other details are available. (CVE-2016-1616)\\n - An unspecified vulnerability exists that is related to history sniffing with HSTS and CSP. No other details are available. (CVE-2016-1617)\\n - A flaw exists in `Blink` due to the weak generation of random numbers by the ARC4-based random number generator. An attacker can exploit this to gain access to sensitive information. No other details are available. (CVE-2016-1618)\\n - An out-of-bounds read error exists in `PDFium` in file `fx_codec_jpx_opj.cpp` in the `sycc4{22,44}_to_rgb()` functions. An attacker can exploit this to cause a denial of service by crashing the application linked using the library. (CVE-2016-1619)\\n - Multiple vulnerabilities exist, the most serious of which allow an attacker to execute arbitrary code via a crafted web page. (CVE-2016-1620)\\n - A flaw in `objects.cc` is triggered when handling cleared `WeakCells`, which may allow a context-dependent attacker to have an unspecified impact. No further details have been provided. (CVE-2016-2051)\",\"family\":\"Web Clients\",\"family_id\":1000020,\"has_patch\":false,\"id\":9062,\"name\":\"Test \\u0026lt; 48.0.2564.82 Multiple Vulnerabilities\",\"risk_factor\":\"HIGH\",\"see_also\":[\"http://testreleases.blogspot.com/2016/01/beta-channel-update_20.html\"],\"solution\":\"Update the browser to 48.0.2564.82 or later.\",\"synopsis\":\"The remote host is utilizing a web browser that is affected by multiple vulnerabilities.\",\"vpr\":{\"drivers\":{\"age_of_vuln\":{\"lower_bound\":366,\"upper_bound\":730},\"cvss3_impact_score\":5.9,\"cvss_impact_score_predicted\":false,\"exploit_code_maturity\":\"UNPROVEN\",\"product_coverage\":\"LOW\",\"threat_intensity_last28\":\"VERY_LOW\",\"threat_sources_last28\":[\"No recorded events\"]},\"score\":5.9,\"updated\":\"2019-12-31T10:08:58Z\"},\"vuln_publication_date\":\"2023-04-18T00:00:00Z\"},\"port\":{\"port\":\"0\",\"protocol\":\"TCP\"},\"scan\":{\"completed_at\":\"2018-12-31T20:59:47Z\",\"schedule_uuid\":\"6f7db010-9cb6-4870-b745-70a2aea2f81ce1b6640fe8a2217b\",\"started_at\":\"2018-12-31T20:59:47Z\",\"uuid\":\"0e55ec5d-c7c7-4673-a618-438a84e9d1b78af3a9957a077904\"},\"severity\":\"low\",\"severity_default_id\":3,\"severity_id\":3,\"severity_modification_type\":\"NONE\",\"state\":\"OPEN\"}", "type": [ "info" ] @@ -854,9 +854,9 @@ An example event for `vulnerability` looks as following: "tracked": true, "uuid": "cf165808-6a31-48e1-9cf3-c6c3174df51d" }, - "first_found": "2018-12-31T20:59:47.000Z", - "indexed": "2022-11-30T14:09:12.061Z", - "last_found": "2018-12-31T20:59:47.000Z", + "first_found": "2026-06-27T09:31:14.000Z", + "indexed": "2026-06-28T09:31:14.000Z", + "last_found": "2026-06-27T09:31:14.000Z", "output": "\n Path : /opt/jdk-11.0.2/\n Installed version : 11.0.2\n Fixed version : Upgrade to a version greater than 11.0.18\n\n\n\n Path : /usr/java/jdk1.8.0_232-cloudera/\n Installed version : 8.0.232\n Fixed version : Upgrade to a version greater than 8u362\n", "package_nested": [ { @@ -1203,26 +1203,26 @@ An example event for `scan` looks as following: ```json { - "@timestamp": "2025-12-03T09:35:39.290Z", + "@timestamp": "2026-07-27T09:30:22.645Z", "agent": { - "ephemeral_id": "6c6451c2-8450-4887-a9dc-d0a16453249c", - "id": "db19321f-465d-4a59-869c-1b771084aa41", - "name": "elastic-agent-46431", + "ephemeral_id": "89c51a06-3c81-4c56-b034-aa89d12c3037", + "id": "7ef6ee8a-3678-479a-b535-b981f847f394", + "name": "elastic-agent-38276", "type": "filebeat", - "version": "9.1.3" + "version": "8.19.0" }, "data_stream": { "dataset": "tenable_io.scan", - "namespace": "47734", + "namespace": "57004", "type": "logs" }, "ecs": { "version": "8.11.0" }, "elastic_agent": { - "id": "db19321f-465d-4a59-869c-1b771084aa41", + "id": "7ef6ee8a-3678-479a-b535-b981f847f394", "snapshot": false, - "version": "9.1.3" + "version": "8.19.0" }, "event": { "agent_id_status": "verified", @@ -1230,10 +1230,9 @@ An example event for `scan` looks as following: "configuration" ], "dataset": "tenable_io.scan", - "ingested": "2025-12-03T09:35:42Z", + "ingested": "2026-07-27T09:30:25Z", "kind": "state", - "module": "tenable_io", - "original": "{\"control\":true,\"creation_date\":1683282785,\"enabled\":true,\"has_triggers\":false,\"id\":195,\"last_modification_date\":1683283158,\"legacy\":false,\"name\":\"Client Discovery\",\"owner\":\"jdoe@contoso.com\",\"permissions\":128,\"policy_id\":194,\"progress\":100,\"read\":false,\"rrules\":\"FREQ=WEEKLY;INTERVAL=1;BYDAY=FR\",\"scan_details\":{\"config_id\":\"a772daba-3d6d-412c-8ee0-3279b19650b2\",\"created_at\":\"2020-02-05T23:11:49.342Z\",\"metadata\":{\"audited_pages\":1,\"crawled_urls\":1,\"queued_pages\":0,\"queued_urls\":0,\"request_count\":74,\"response_time\":0,\"scan_status\":\"stopping\"},\"requested_action\":\"start\",\"scan_id\":\"195\",\"status\":\"completed\",\"target\":\"http://192.0.2.119\",\"updated_at\":\"2020-02-05T23:22:15.510Z\",\"user_id\":\"53e1d711-f18f-4a75-a86e-1c47bccff1b7\"},\"schedule_uuid\":\"11c56dea-as5f-65ce-ad45-9978045df65ecade45b6e3a76871\",\"shared\":true,\"starttime\":\"20220708T033000\",\"status\":\"completed\",\"status_times\":{\"initializing\":2623,\"pending\":52799,\"processing\":1853,\"publishing\":300329,\"running\":15759},\"template_uuid\":\"a1efc3b4-cd45-a65d-fbc4-0079ebef4a56cd32a05ec2812bcf\",\"timezone\":\"America/Los_Angeles\",\"total_targets\":21,\"type\":\"remote\",\"user_permissions\":128,\"uuid\":\"a456ef1c-cbd4-ad41-f654-119b766ff61f\",\"wizard_uuid\":\"32cbd657-fe65-a45e-a45f-0079eb89e56a1c23fd5ec2812bcf\"}", + "original": "{\"control\":true,\"creation_date\":1683282785,\"enabled\":true,\"has_triggers\":false,\"id\":195,\"last_modification_date\":1683283158,\"legacy\":false,\"name\":\"Client Discovery\",\"owner\":\"jdoe@contoso.com\",\"permissions\":128,\"policy_id\":194,\"progress\":100,\"read\":false,\"rrules\":\"FREQ=WEEKLY;INTERVAL=1;BYDAY=FR\",\"scan_details\":{\"history\":[{\"alt_targets_used\":false,\"creation_date\":1683282785,\"history_id\":1000195,\"is_archived\":false,\"last_modification_date\":1683283158,\"owner_id\":1,\"scheduler\":0,\"status\":\"completed\",\"type\":\"remote\",\"uuid\":\"a456ef1c-cbd4-ad41-f654-119b766ff61f\"}],\"hosts\":[{\"asset_id\":5,\"critical\":0,\"high\":3,\"host_id\":5,\"host_index\":0,\"hostname\":\"192.0.2.57\",\"info\":156,\"low\":1,\"medium\":6,\"numchecksconsidered\":100,\"progress\":\"100-100/200-200\",\"scanprogresscurrent\":100,\"scanprogresstotal\":100,\"score\":3766,\"severity\":166,\"severitycount\":{\"item\":[{\"count\":156,\"severitylevel\":0},{\"count\":1,\"severitylevel\":1},{\"count\":6,\"severitylevel\":2},{\"count\":3,\"severitylevel\":3},{\"count\":0,\"severitylevel\":4}]},\"totalchecksconsidered\":100}],\"info\":{\"acls\":[{\"display_name\":\"jdoe@contoso.com\",\"id\":1,\"name\":\"jdoe@contoso.com\",\"owner\":1,\"permissions\":128,\"type\":\"user\"}],\"alt_targets_used\":false,\"control\":true,\"edit_allowed\":true,\"folder_id\":226,\"hasaudittrail\":true,\"haskb\":true,\"hostcount\":1,\"is_archived\":false,\"name\":\"Client Discovery\",\"no_target\":false,\"object_id\":195,\"owner\":\"jdoe@contoso.com\",\"pci-can-upload\":false,\"policy\":null,\"scan_end\":1683283158,\"scan_start\":1683282785,\"scan_type\":\"remote\",\"scanner_end\":null,\"scanner_name\":null,\"scanner_start\":null,\"schedule_uuid\":\"11c56dea-as5f-65ce-ad45-9978045df65ecade45b6e3a76871\",\"shared\":true,\"status\":\"completed\",\"tag_targets\":[],\"targets\":\"192.0.2.57\",\"timestamp\":1683283158,\"user_permissions\":128,\"uuid\":\"a456ef1c-cbd4-ad41-f654-119b766ff61f\"},\"vulnerabilities\":[{\"count\":3,\"plugin_family\":\"Port scanners\",\"plugin_id\":34220,\"plugin_name\":\"Netstat Portscanner (WMI)\",\"severity\":0,\"vuln_index\":1}]},\"schedule_uuid\":\"11c56dea-as5f-65ce-ad45-9978045df65ecade45b6e3a76871\",\"shared\":true,\"starttime\":\"20220708T033000\",\"status\":\"completed\",\"status_times\":{\"initializing\":2623,\"pending\":52799,\"processing\":1853,\"publishing\":300329,\"running\":15759},\"template_uuid\":\"a1efc3b4-cd45-a65d-fbc4-0079ebef4a56cd32a05ec2812bcf\",\"timezone\":\"America/Los_Angeles\",\"total_targets\":21,\"type\":\"remote\",\"user_permissions\":128,\"uuid\":\"a456ef1c-cbd4-ad41-f654-119b766ff61f\",\"wizard_uuid\":\"32cbd657-fe65-a45e-a45f-0079eb89e56a1c23fd5ec2812bcf\"}", "type": [ "info" ] @@ -1241,6 +1240,11 @@ An example event for `scan` looks as following: "input": { "type": "cel" }, + "related": { + "ip": [ + "192.0.2.57" + ] + }, "tags": [ "preserve_original_event", "forwarded", @@ -1263,23 +1267,109 @@ An example event for `scan` looks as following: "read": false, "rrules": "FREQ=WEEKLY;INTERVAL=1;BYDAY=FR", "scan_details": { - "config_id": "a772daba-3d6d-412c-8ee0-3279b19650b2", - "created_at": "2020-02-05T23:11:49.342Z", - "metadata": { - "audited_pages": 1, - "crawled_urls": 1, - "queued_pages": 0, - "queued_urls": 0, - "request_count": 74, - "response_time": 0, - "scan_status": "stopping" + "history": [ + { + "alt_targets_used": false, + "creation_date": "2023-05-05T10:33:05.000Z", + "history_id": 1000195, + "is_archived": false, + "last_modification_date": "2023-05-05T10:39:18.000Z", + "owner_id": 1, + "scheduler": 0, + "status": "completed", + "type": "remote", + "uuid": "a456ef1c-cbd4-ad41-f654-119b766ff61f" + } + ], + "hosts": [ + { + "asset_id": 5, + "critical": 0, + "high": 3, + "host_id": 5, + "host_index": 0, + "hostname": "192.0.2.57", + "info": 156, + "low": 1, + "medium": 6, + "numchecksconsidered": 100, + "progress": "100-100/200-200", + "scanprogresscurrent": 100, + "scanprogresstotal": 100, + "score": 3766, + "severity": 166, + "severitycount": { + "item": [ + { + "count": 156, + "severitylevel": 0 + }, + { + "count": 1, + "severitylevel": 1 + }, + { + "count": 6, + "severitylevel": 2 + }, + { + "count": 3, + "severitylevel": 3 + }, + { + "count": 0, + "severitylevel": 4 + } + ] + }, + "totalchecksconsidered": 100 + } + ], + "info": { + "acls": [ + { + "display_name": "jdoe@contoso.com", + "id": 1, + "name": "jdoe@contoso.com", + "owner": 1, + "permissions": 128, + "type": "user" + } + ], + "alt_targets_used": false, + "control": true, + "edit_allowed": true, + "folder_id": 226, + "hasaudittrail": true, + "haskb": true, + "hostcount": 1, + "is_archived": false, + "name": "Client Discovery", + "no_target": false, + "object_id": 195, + "owner": "jdoe@contoso.com", + "pci-can-upload": false, + "scan_end": "2023-05-05T10:39:18.000Z", + "scan_start": "2023-05-05T10:33:05.000Z", + "scan_type": "remote", + "schedule_uuid": "11c56dea-as5f-65ce-ad45-9978045df65ecade45b6e3a76871", + "shared": true, + "status": "completed", + "targets": "192.0.2.57", + "timestamp": "2023-05-05T10:39:18.000Z", + "user_permissions": 128, + "uuid": "a456ef1c-cbd4-ad41-f654-119b766ff61f" }, - "requested_action": "start", - "scan_id": "195", - "status": "completed", - "target": "http://192.0.2.119", - "updated_at": "2020-02-05T23:22:15.510Z", - "user_id": "53e1d711-f18f-4a75-a86e-1c47bccff1b7" + "vulnerabilities": [ + { + "count": 3, + "plugin_family": "Port scanners", + "plugin_id": 34220, + "plugin_name": "Netstat Portscanner (WMI)", + "severity": 0, + "vuln_index": 1 + } + ] }, "schedule_uuid": "11c56dea-as5f-65ce-ad45-9978045df65ecade45b6e3a76871", "shared": true, @@ -1334,21 +1424,114 @@ An example event for `scan` looks as following: | tenable_io.scan.progress | The progress of the scan ranging from 0 to 100. | long | | tenable_io.scan.read | A value indicating whether the user account associated with the request message has viewed the scan in the Tenable Vulnerability Management user interface. If 1, the user account has viewed the scan results. | boolean | | tenable_io.scan.rrules | The interval at which the scan repeats. The interval is formatted as a string of three values delimited by semi-colons. These values are the frequency (FREQ=ONETIME or DAILY or WEEKLY or MONTHLY or YEARLY), the interval (INTERVAL=1 or 2 or 3 ... x), and the days of the week (BYDAY=SU,MO,TU,WE,TH,FR,SA). For a scan that runs every three weeks on Monday Wednesday and Friday, the string would be FREQ=WEEKLY;INTERVAL=3;BYDAY=MO,WE,FR. If the scan is not scheduled to recur, this attribute is null. For more information, see rrules Format. | keyword | -| tenable_io.scan.scan_details.config_id | The unique identifier of the scan configuration. | keyword | -| tenable_io.scan.scan_details.created_at | The date and time when the scan was created. | date | -| tenable_io.scan.scan_details.metadata.audited_pages | The number of pages that have been audited. | long | -| tenable_io.scan.scan_details.metadata.crawled_urls | The number of URLs that have been crawled. | long | -| tenable_io.scan.scan_details.metadata.queued_pages | The number of pages queued for auditing. | long | -| tenable_io.scan.scan_details.metadata.queued_urls | The number of URLs queued for scanning. | long | -| tenable_io.scan.scan_details.metadata.request_count | The total number of requests made during the scan. | long | -| tenable_io.scan.scan_details.metadata.response_time | The average response time in milliseconds. | long | -| tenable_io.scan.scan_details.metadata.scan_status | The detailed scan status. | keyword | -| tenable_io.scan.scan_details.requested_action | The action requested for the scan (e.g., start, stop). | keyword | -| tenable_io.scan.scan_details.scan_id | The unique identifier for the scan. | keyword | -| tenable_io.scan.scan_details.status | The current status of the scan. | keyword | -| tenable_io.scan.scan_details.target | The target URL of the scan. | keyword | -| tenable_io.scan.scan_details.updated_at | The date and time when the scan was last updated. | date | -| tenable_io.scan.scan_details.user_id | The unique identifier of the user who created the scan. | keyword | +| tenable_io.scan.scan_details.comphosts.asset_id | The unique ID of the asset. | long | +| tenable_io.scan.scan_details.comphosts.critical | The number of critical-severity findings on the host. | long | +| tenable_io.scan.scan_details.comphosts.high | The number of high-severity findings on the host. | long | +| tenable_io.scan.scan_details.comphosts.host_id | The unique ID of the host. | long | +| tenable_io.scan.scan_details.comphosts.host_index | The index for the host. | long | +| tenable_io.scan.scan_details.comphosts.hostname | The name of the host. | keyword | +| tenable_io.scan.scan_details.comphosts.info | The number of informational findings on the host. | long | +| tenable_io.scan.scan_details.comphosts.low | The number of low-severity findings on the host. | long | +| tenable_io.scan.scan_details.comphosts.medium | The number of medium-severity findings on the host. | long | +| tenable_io.scan.scan_details.comphosts.numchecksconsidered | The number of checks considered on the host. | long | +| tenable_io.scan.scan_details.comphosts.progress | The scan progress of the host. | keyword | +| tenable_io.scan.scan_details.comphosts.scanprogresscurrent | The current scan progress for the host. | long | +| tenable_io.scan.scan_details.comphosts.scanprogresstotal | The total scan progress for the host. | long | +| tenable_io.scan.scan_details.comphosts.score | The overall score for the host. | long | +| tenable_io.scan.scan_details.comphosts.severity | The total severity count for the host. | long | +| tenable_io.scan.scan_details.comphosts.severitycount.item.count | The number of findings at this severity level. | long | +| tenable_io.scan.scan_details.comphosts.severitycount.item.severitylevel | The severity level (0=info, 1=low, 2=medium, 3=high, 4=critical). | long | +| tenable_io.scan.scan_details.comphosts.totalchecksconsidered | The total number of checks considered on the host. | long | +| tenable_io.scan.scan_details.compliance.count | The number of findings. | long | +| tenable_io.scan.scan_details.compliance.host_id | The unique ID of the host. | long | +| tenable_io.scan.scan_details.compliance.hostname | The name of the host. | keyword | +| tenable_io.scan.scan_details.compliance.plugin_family | The parent family of the compliance plugin. | keyword | +| tenable_io.scan.scan_details.compliance.plugin_id | The unique ID of the compliance plugin (hash string). | keyword | +| tenable_io.scan.scan_details.compliance.plugin_name | The name of the compliance plugin. | keyword | +| tenable_io.scan.scan_details.compliance.severity | The severity rating of the plugin. | long | +| tenable_io.scan.scan_details.compliance.severity_index | The severity index order of the plugin. | long | +| tenable_io.scan.scan_details.history.alt_targets_used | If true, the scan was not launched with a target list. | boolean | +| tenable_io.scan.scan_details.history.creation_date | The creation date for the historical data in Unix time. | date | +| tenable_io.scan.scan_details.history.history_id | The unique ID of the historical data. | long | +| tenable_io.scan.scan_details.history.is_archived | Indicates whether the scan results are older than 35 days. | boolean | +| tenable_io.scan.scan_details.history.last_modification_date | The last modification date for the historical data in Unix time. | date | +| tenable_io.scan.scan_details.history.owner_id | The unique ID of the owner of the scan. | long | +| tenable_io.scan.scan_details.history.reporting_mode | Reporting mode for Nessus Agent scans (baseline, differential, or null). | keyword | +| tenable_io.scan.scan_details.history.scheduler | If true, Tenable Vulnerability Management launched the scan from a schedule. | long | +| tenable_io.scan.scan_details.history.status | The terminal status of the scan run. | keyword | +| tenable_io.scan.scan_details.history.type | The type of scan (local, remote, agent, or null). | keyword | +| tenable_io.scan.scan_details.history.uuid | The UUID of the historical data. | keyword | +| tenable_io.scan.scan_details.hosts.asset_id | The unique ID of the asset. | long | +| tenable_io.scan.scan_details.hosts.critical | The number of critical-severity findings on the host. | long | +| tenable_io.scan.scan_details.hosts.high | The number of high-severity findings on the host. | long | +| tenable_io.scan.scan_details.hosts.host_id | The unique ID of the host. | long | +| tenable_io.scan.scan_details.hosts.host_index | The index for the host. | long | +| tenable_io.scan.scan_details.hosts.hostname | The name of the host. | keyword | +| tenable_io.scan.scan_details.hosts.info | The number of informational findings on the host. | long | +| tenable_io.scan.scan_details.hosts.low | The number of low-severity findings on the host. | long | +| tenable_io.scan.scan_details.hosts.medium | The number of medium-severity findings on the host. | long | +| tenable_io.scan.scan_details.hosts.numchecksconsidered | The number of checks considered on the host. | long | +| tenable_io.scan.scan_details.hosts.progress | The scan progress of the host. | keyword | +| tenable_io.scan.scan_details.hosts.scanprogresscurrent | The current scan progress for the host. | long | +| tenable_io.scan.scan_details.hosts.scanprogresstotal | The total scan progress for the host. | long | +| tenable_io.scan.scan_details.hosts.score | The overall score for the host. | long | +| tenable_io.scan.scan_details.hosts.severity | The total severity count for the host. | long | +| tenable_io.scan.scan_details.hosts.severitycount.item.count | The number of findings at this severity level. | long | +| tenable_io.scan.scan_details.hosts.severitycount.item.severitylevel | The severity level (0=info, 1=low, 2=medium, 3=high, 4=critical). | long | +| tenable_io.scan.scan_details.hosts.totalchecksconsidered | The total number of checks considered on the host. | long | +| tenable_io.scan.scan_details.info.acls.display_name | The name of the user or group as it appears in the UI. | keyword | +| tenable_io.scan.scan_details.info.acls.id | A number representing the display order of the user or group. | long | +| tenable_io.scan.scan_details.info.acls.name | The name of the user or group granted the specified permissions. | keyword | +| tenable_io.scan.scan_details.info.acls.owner | Indicates whether the user or group owns the scan. | long | +| tenable_io.scan.scan_details.info.acls.permissions | The scan permission. | long | +| tenable_io.scan.scan_details.info.acls.type | The type of scan permissions (default, user, or group). | keyword | +| tenable_io.scan.scan_details.info.alt_targets_used | If true, Tenable Vulnerability Management did not launch the scan with a target list. | boolean | +| tenable_io.scan.scan_details.info.control | If true, the scan has a schedule and can be launched. | boolean | +| tenable_io.scan.scan_details.info.edit_allowed | If true, the requesting user can edit this scan configuration. | boolean | +| tenable_io.scan.scan_details.info.folder_id | The unique ID of the destination folder for the scan. | long | +| tenable_io.scan.scan_details.info.hasaudittrail | Indicates whether the scan is configured to create an audit trail. | boolean | +| tenable_io.scan.scan_details.info.haskb | Indicates whether a scan has a Knowledge Base (KB) associated with it. | boolean | +| tenable_io.scan.scan_details.info.hostcount | The total number of assets scanned for vulnerabilities. | long | +| tenable_io.scan.scan_details.info.is_archived | Indicates whether the scan results are older than 35 days. | boolean | +| tenable_io.scan.scan_details.info.name | The name of the scan. | keyword | +| tenable_io.scan.scan_details.info.no_target | Indicates whether the scan based on this policy can specify targets. | boolean | +| tenable_io.scan.scan_details.info.object_id | The unique ID of the scan result object. | long | +| tenable_io.scan.scan_details.info.owner | The owner of the scan. | keyword | +| tenable_io.scan.scan_details.info.pci-can-upload | If true, you can submit the results of the scan for PCI ASV review. | boolean | +| tenable_io.scan.scan_details.info.policy | The name of the scan template associated with the scan. | keyword | +| tenable_io.scan.scan_details.info.scan_end | The Unix timestamp when the scan run finished. | date | +| tenable_io.scan.scan_details.info.scan_start | The Unix timestamp when the scan run started. | date | +| tenable_io.scan.scan_details.info.scan_type | The type of scan (ps, remote, agent, or null). | keyword | +| tenable_io.scan.scan_details.info.scanner_end | The scan's end time, if the scan is imported. | date | +| tenable_io.scan.scan_details.info.scanner_name | The name of the scanner configured to run the scan. | keyword | +| tenable_io.scan.scan_details.info.scanner_start | The scan's start time, if the scan is imported. | date | +| tenable_io.scan.scan_details.info.schedule_uuid | The UUID for a specific instance in the scan schedule. | keyword | +| tenable_io.scan.scan_details.info.shared | If true, the scan is shared with users other than the owner. | boolean | +| tenable_io.scan.scan_details.info.status | The status of the scan. | keyword | +| tenable_io.scan.scan_details.info.tag_targets | The list of asset tag UUIDs the scan uses to determine which assets it evaluates. | keyword | +| tenable_io.scan.scan_details.info.targets | A comma-delimited list of IPv4 addresses configured as targets for the scan. | keyword | +| tenable_io.scan.scan_details.info.timestamp | The Unix timestamp when the scan run finished. | date | +| tenable_io.scan.scan_details.info.user_permissions | The sharing permissions for the scan. | long | +| tenable_io.scan.scan_details.info.uuid | The UUID of the scan. | keyword | +| tenable_io.scan.scan_details.notes.message | The specific message of the note. | keyword | +| tenable_io.scan.scan_details.notes.severity | The severity of the note. | long | +| tenable_io.scan.scan_details.notes.title | The title of the note. | keyword | +| tenable_io.scan.scan_details.progress | The progress of the scan ranging from 0 to 100. | long | +| tenable_io.scan.scan_details.remediations.num_cves | The number of CVEs addressed by the remediations. | long | +| tenable_io.scan.scan_details.remediations.num_hosts | The number of hosts with remediations. | long | +| tenable_io.scan.scan_details.remediations.num_impacted_hosts | The number of hosts impacted by the remediations. | long | +| tenable_io.scan.scan_details.remediations.num_remediated_cves | The number of CVEs that have been remediated. | long | +| tenable_io.scan.scan_details.remediations.remediations.hosts | The number of hosts affected by this remediation. | long | +| tenable_io.scan.scan_details.remediations.remediations.remediation | A description of the remediation action. | keyword | +| tenable_io.scan.scan_details.remediations.remediations.value | The unique identifier of the remediation. | keyword | +| tenable_io.scan.scan_details.remediations.remediations.vulns | The number of vulnerabilities addressed by this remediation. | long | +| tenable_io.scan.scan_details.vulnerabilities.count | The number of vulnerabilities found. | long | +| tenable_io.scan.scan_details.vulnerabilities.plugin_family | The parent family of the vulnerability plugin. | keyword | +| tenable_io.scan.scan_details.vulnerabilities.plugin_id | The unique ID of the vulnerability plugin. | long | +| tenable_io.scan.scan_details.vulnerabilities.plugin_name | The name of the vulnerability plugin. | keyword | +| tenable_io.scan.scan_details.vulnerabilities.severity | The severity rating of the plugin. | long | +| tenable_io.scan.scan_details.vulnerabilities.severity_index | The severity index order of the plugin. | long | +| tenable_io.scan.scan_details.vulnerabilities.vuln_index | The index of the vulnerability plugin. | long | | tenable_io.scan.schedule_uuid | The UUID for a specific instance in the scan schedule. | keyword | | tenable_io.scan.shared | If true, the scan is shared with users other than the scan owner. The level of sharing is specified in the acls attribute of the scan details. | boolean | | tenable_io.scan.starttime | For one-time scans, the starting time and date for the scan. For recurrent scans, the first date on which the scan schedule is active and the time that recurring scans launch based on the rrules attribute. | date | diff --git a/packages/tenable_io/manifest.yml b/packages/tenable_io/manifest.yml index 5b060e2bea1..406cdb06926 100644 --- a/packages/tenable_io/manifest.yml +++ b/packages/tenable_io/manifest.yml @@ -1,7 +1,7 @@ format_version: "3.4.0" name: tenable_io title: Tenable Vulnerability Management -version: "4.12.0" +version: "4.12.1" description: Collect logs from Tenable Vulnerability Management with Elastic Agent. type: integration categories: