Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion packages/tenable_io/_dev/build/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ The Tenable Vulnerability Management integration collects logs for five types of

**Vulnerability** is used to retrieve all vulnerabilities on each asset, including the vulnerability state. See more details in the API documentation [here](https://developer.tenable.com/reference/exports-vulns-request-export).

**Scan** is used to retrieve details about existing scans and scan details, including scan statuses, assigned targets, and more. See more details in the API documentation for [Scan](https://developer.tenable.com/reference/scans-list) and [Scan Details](https://developer.tenable.com/reference/was-v2-scans-details).
**Scan** is used to retrieve details about existing scans and scan details, including scan statuses, assigned targets, and more. See more details in the API documentation for [Scan](https://developer.tenable.com/reference/scans-list) and [Scan Details](https://developer.tenable.com/reference/scans-details).

## Compatibility

Expand Down
12 changes: 4 additions & 8 deletions packages/tenable_io/_dev/deploy/docker/files/config.yml
Original file line number Diff line number Diff line change
Expand Up @@ -71,22 +71,18 @@ rules:
{"id":226,"name":"Targeted Scans","type":"custom","custom":1,"unread_count":0,"default_tag":0}
]
}
- path: /was/v2/scans/195
- path: /scans/195
methods: ["GET"]
responses:
- status_code: 200
body: |
{
"scan_id":"195","user_id":"53e1d711-f18f-4a75-a86e-1c47bccff1b7","config_id":"a772daba-3d6d-412c-8ee0-3279b19650b2","target":"http://192.0.2.119","created_at":"2020-02-05T23:11:49.342Z","updated_at":"2020-02-05T23:22:15.510Z","requested_action":"start","status":"completed","metadata":{"queued_urls":0,"scan_status":"stopping","crawled_urls":1,"queued_pages":0,"audited_pages":1,"request_count":74,"response_time":0}
}
- path: /was/v2/scans/423
{"info":{"owner":"jdoe@contoso.com","name":"Client Discovery","no_target":false,"folder_id":226,"control":true,"user_permissions":128,"schedule_uuid":"11c56dea-as5f-65ce-ad45-9978045df65ecade45b6e3a76871","edit_allowed":true,"scanner_name":null,"policy":null,"shared":true,"object_id":195,"tag_targets":[],"hostcount":1,"uuid":"a456ef1c-cbd4-ad41-f654-119b766ff61f","status":"completed","scan_type":"remote","targets":"192.0.2.57","alt_targets_used":false,"pci-can-upload":false,"scan_start":1683282785,"timestamp":1683283158,"is_archived":false,"scan_end":1683283158,"haskb":true,"hasaudittrail":true,"scanner_start":null,"scanner_end":null,"acls":[{"permissions":128,"owner":1,"display_name":"jdoe@contoso.com","name":"jdoe@contoso.com","id":1,"type":"user"}]},"history":[{"history_id":1000195,"owner_id":1,"creation_date":1683282785,"last_modification_date":1683283158,"uuid":"a456ef1c-cbd4-ad41-f654-119b766ff61f","type":"remote","status":"completed","scheduler":0,"alt_targets_used":false,"is_archived":false}],"hosts":[{"asset_id":5,"host_id":5,"hostname":"192.0.2.57","progress":"100-100/200-200","scanprogresscurrent":100,"scanprogresstotal":100,"numchecksconsidered":100,"totalchecksconsidered":100,"severitycount":{"item":[{"count":156,"severitylevel":0},{"count":1,"severitylevel":1},{"count":6,"severitylevel":2},{"count":3,"severitylevel":3},{"count":0,"severitylevel":4}]},"severity":166,"score":3766,"info":156,"low":1,"medium":6,"high":3,"critical":0,"host_index":0}],"vulnerabilities":[{"count":3,"plugin_id":34220,"plugin_name":"Netstat Portscanner (WMI)","severity":0,"plugin_family":"Port scanners","vuln_index":1}]}
- path: /scans/423
methods: ["GET"]
responses:
- status_code: 200
body: |
{
"scan_id":"423","user_id":"53e1d711-f18f-4a75-a86e-1c47bccff1b7","config_id":"a772daba-3d6d-412c-8ee0-3279b19650b2","target":"http://192.0.2.119","created_at":"2020-02-05T23:11:49.342Z","updated_at":"2020-02-05T23:22:15.510Z","requested_action":"start","status":"completed","metadata":{"queued_urls":0,"scan_status":"stopping","crawled_urls":1,"queued_pages":0,"audited_pages":1,"request_count":74,"response_time":0}
}
{"info":{"owner":"jdoe@contoso.com","name":"Client Vulnerabiltiy Scan Group B","no_target":false,"folder_id":227,"control":true,"user_permissions":128,"schedule_uuid":"1d63c64e-a5d1-df57-0ecf-9f0e288d8a45fe84bcd54e39daaf","edit_allowed":true,"scanner_name":null,"policy":null,"shared":true,"object_id":423,"tag_targets":[],"hostcount":1,"uuid":"a2389003-fec1-a45d-a45d-aece258c4133","status":"completed","scan_type":"remote","targets":"192.0.2.0/24","alt_targets_used":false,"pci-can-upload":false,"scan_start":1683043551,"timestamp":1683049400,"is_archived":false,"scan_end":1683049400,"haskb":true,"hasaudittrail":true,"scanner_start":null,"scanner_end":null,"acls":[{"permissions":128,"owner":1,"display_name":"jdoe@contoso.com","name":"jdoe@contoso.com","id":1,"type":"user"}]},"history":[{"history_id":1000423,"owner_id":1,"creation_date":1683043551,"last_modification_date":1683049400,"uuid":"a2389003-fec1-a45d-a45d-aece258c4133","type":"remote","status":"completed","scheduler":0,"alt_targets_used":false,"is_archived":false}],"hosts":[{"asset_id":3,"host_id":3,"hostname":"192.0.2.57","progress":"100-100/200-200","scanprogresscurrent":100,"scanprogresstotal":100,"numchecksconsidered":100,"totalchecksconsidered":100,"severitycount":{"item":[{"count":52,"severitylevel":0},{"count":11,"severitylevel":1},{"count":100,"severitylevel":2},{"count":58,"severitylevel":3},{"count":32,"severitylevel":4}]},"severity":253,"score":388162,"info":52,"low":11,"medium":100,"high":58,"critical":32,"host_index":0}],"vulnerabilities":[{"count":65,"plugin_id":34252,"plugin_name":"Microsoft Windows Remote Listeners Enumeration (WMI)","severity":0,"plugin_family":"Windows","vuln_index":1}]}
- path: /audit-log/v1/events
methods: ["GET"]
query_params:
Expand Down
5 changes: 5 additions & 0 deletions packages/tenable_io/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "4.12.1"
changes:
- description: Replace the scan details endpoint with GET /scans/{id} and remap the scan_details fields to the standard VM scan-details schema.
type: bugfix

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changelog entry is marked as type: bugfix under 4.13.0 (minor), but this change removes the published WAS scan_details.* fields and replaces them with the VM schema. Since it introduces a breaking schema change, it should be classified as a breaking-change and released as a major version.

If it's truly a bugfix, it should be a patch release (e.g., 4.12.1). As it stands, 4.13.0 with type: bugfix is inconsistent.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is not a breaking change since the previous code never worked. However, yes, this should bump patch.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I just thought it is a change it worths a minor version bump because of the size of the change. If you both think it should be a patch version despite the changes it includes that's ok for me.

link: https://github.com/elastic/integrations/pull/20347
- version: "4.12.0"
changes:
- description: Allow user configuration of maximum number of CEL executions for the asset, audit, plugin, and scan data streams.
Expand Down
18 changes: 9 additions & 9 deletions packages/tenable_io/data_stream/asset/sample_event.json
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
{
"@timestamp": "2018-12-31T22:27:58.599Z",
"agent": {
"ephemeral_id": "f945f2c2-fbaf-4b93-b6ca-7d51e6a0706d",
"id": "a0570906-16fc-4c38-821f-7c3aa6ed04bb",
"name": "docker-fleet-agent",
"ephemeral_id": "d1524bb7-93f3-43e5-a4e8-691b38ada6fc",
"id": "42f9eef6-3014-478c-b828-bbcbda65cf4f",
"name": "elastic-agent-15508",
"type": "filebeat",
"version": "8.12.0"
"version": "8.19.0"
},
"cloud": {
"availability_zone": "12",
Expand All @@ -18,24 +18,24 @@
},
"data_stream": {
"dataset": "tenable_io.asset",
"namespace": "ep",
"namespace": "54262",
"type": "logs"
},
"ecs": {
"version": "8.11.0"
},
"elastic_agent": {
"id": "a0570906-16fc-4c38-821f-7c3aa6ed04bb",
"id": "42f9eef6-3014-478c-b828-bbcbda65cf4f",
"snapshot": false,
"version": "8.12.0"
"version": "8.19.0"
},
"event": {
"agent_id_status": "verified",
"category": [
"host"
],
"dataset": "tenable_io.asset",
"ingested": "2024-04-02T09:13:00Z",
"ingested": "2026-07-27T09:27:59Z",
"kind": "state",
"original": "{\"acr_score\":\"3\",\"agent_names\":[],\"agent_uuid\":\"22\",\"aws_availability_zone\":null,\"aws_ec2_instance_ami_id\":\"12\",\"aws_ec2_instance_group_name\":null,\"aws_ec2_instance_id\":\"12\",\"aws_ec2_instance_state_name\":null,\"aws_ec2_instance_type\":null,\"aws_ec2_name\":null,\"aws_ec2_product_code\":null,\"aws_owner_id\":\"44\",\"aws_region\":null,\"aws_subnet_id\":null,\"aws_vpc_id\":null,\"azure_resource_id\":\"12\",\"azure_vm_id\":\"12\",\"bigfix_asset_id\":null,\"bios_uuid\":\"33\",\"created_at\":\"2017-12-31T20:40:44.535Z\",\"deleted_at\":\"2017-12-31T20:40:44.535Z\",\"deleted_by\":\"user\",\"exposure_score\":\"721\",\"first_scan_time\":\"2017-12-31T20:40:23.447Z\",\"first_seen\":\"2017-12-31T20:40:23.447Z\",\"fqdns\":[\"example.com\"],\"gcp_instance_id\":\"12\",\"gcp_project_id\":\"12\",\"gcp_zone\":\"12\",\"has_agent\":false,\"has_plugin_results\":true,\"hostnames\":[],\"id\":\"95c2725c-7298-4a44-8a1d-63131ca3f01f\",\"installed_software\":[\"cpe:/a:test:xyz:12.8\",\"cpe:/a:test:abc:7.7.3\",\"cpe:/a:test:pqr:6.9\",\"cpe:/a:test:xyz\"],\"ipv4s\":[\"89.160.20.112\"],\"ipv6s\":[],\"last_authenticated_scan_date\":\"2017-12-31T20:40:44.535Z\",\"last_licensed_scan_date\":\"2018-12-31T22:27:52.869Z\",\"last_scan_id\":\"00283024-afee-44ea-b467-db5a6ed9fd50ab8f7ecb158c480e\",\"last_scan_time\":\"2018-03-31T22:27:52.869Z\",\"last_schedule_id\":\"72284901-7c68-42b2-a0c4-c1e75568849df60557ee0e264228\",\"last_seen\":\"2018-12-31T22:27:52.869Z\",\"mac_addresses\":[],\"manufacturer_tpm_ids\":[],\"mcafee_epo_agent_guid\":null,\"mcafee_epo_guid\":null,\"netbios_names\":[],\"network_interfaces\":[{\"fqdns\":[\"example.com\"],\"ipv4s\":[\"89.160.20.112\",\"81.2.69.144\"],\"ipv6s\":[\"2a02:cf40::\"],\"mac_addresses\":[\"00-00-5E-00-53-00\",\"00-00-5E-00-53-FF\"],\"name\":\"test.0.1234\"}],\"operating_systems\":[],\"qualys_asset_ids\":[],\"qualys_host_ids\":[],\"servicenow_sysid\":null,\"sources\":[{\"first_seen\":\"2017-12-31T20:40:23.447Z\",\"last_seen\":\"2018-12-31T22:27:52.869Z\",\"name\":\"TEST_SCAN\"}],\"ssh_fingerprints\":[],\"symantec_ep_hardware_keys\":[],\"system_types\":[],\"tags\":[{\"added_at\":\"2018-12-31T14:53:13.817Z\",\"added_by\":\"ac2e7ef6-fac9-47bf-9170-617331322885\",\"key\":\"Geographic Area\",\"uuid\":\"47e7f5f6-1013-4401-a705-479bfadc7826\",\"value\":\"APAC\"}],\"terminated_at\":\"2017-12-31T20:40:44.535Z\",\"terminated_by\":\"user\",\"updated_at\":\"2018-12-31T22:27:58.599Z\"}",
"type": [
Expand Down Expand Up @@ -162,4 +162,4 @@
"updated_at": "2018-12-31T22:27:58.599Z"
}
}
}
}
16 changes: 8 additions & 8 deletions packages/tenable_io/data_stream/audit/sample_event.json
Original file line number Diff line number Diff line change
@@ -1,24 +1,24 @@
{
"@timestamp": "2018-12-31T01:40:07.000Z",
"agent": {
"ephemeral_id": "2b353f6e-e21d-4e61-a426-9b582471c1fa",
"id": "1a70a431-df2f-4f16-9352-a30f75fb1df2",
"name": "elastic-agent-83695",
"ephemeral_id": "48852dc2-5fcd-43e2-9dcf-91f496198616",
"id": "54bb10de-7dac-4d6f-8f76-b0fa753a6755",
"name": "elastic-agent-12062",
"type": "filebeat",
"version": "8.18.1"
"version": "8.19.0"
},
"data_stream": {
"dataset": "tenable_io.audit",
"namespace": "31446",
"namespace": "73649",
"type": "logs"
},
"ecs": {
"version": "8.11.0"
},
"elastic_agent": {
"id": "1a70a431-df2f-4f16-9352-a30f75fb1df2",
"id": "54bb10de-7dac-4d6f-8f76-b0fa753a6755",
"snapshot": false,
"version": "8.18.1"
"version": "8.19.0"
},
"event": {
"action": "session-delete",
Expand All @@ -28,7 +28,7 @@
],
"dataset": "tenable_io.audit",
"id": "eaac53481de04f67bc7eeea07d2fb0f5",
"ingested": "2025-06-03T16:34:47Z",
"ingested": "2026-07-27T09:28:46Z",
"kind": "event",
"original": "{\"action\":\"session.delete\",\"actor\":{\"id\":\"d2667922-5a27-4c4a-9207-f591fbdc9d23\",\"name\":\"user2@example.com\"},\"crud\":\"d\",\"description\":null,\"fields\":[{\"key\":\"message\",\"value\":\"session timeout\"}],\"id\":\"eaac53481de04f67bc7eeea07d2fb0f5\",\"is_anonymous\":null,\"is_failure\":false,\"received\":\"2018-12-31T01:40:07Z\",\"target\":{\"id\":\"12d024e\",\"name\":null,\"type\":\"Session\"}}",
"outcome": "success",
Expand Down
18 changes: 9 additions & 9 deletions packages/tenable_io/data_stream/plugin/sample_event.json
Original file line number Diff line number Diff line change
@@ -1,29 +1,29 @@
{
"@timestamp": "2018-07-19T00:00:00.000Z",
"agent": {
"ephemeral_id": "f945f2c2-fbaf-4b93-b6ca-7d51e6a0706d",
"id": "a0570906-16fc-4c38-821f-7c3aa6ed04bb",
"name": "docker-fleet-agent",
"ephemeral_id": "30513499-3121-45dd-8e75-67e3b042d3a1",
"id": "1fa7cf0a-419d-4967-a86b-696c132d365d",
"name": "elastic-agent-96491",
"type": "filebeat",
"version": "8.12.0"
"version": "8.19.0"
},
"data_stream": {
"dataset": "tenable_io.plugin",
"namespace": "ep",
"namespace": "72547",
"type": "logs"
},
"ecs": {
"version": "8.11.0"
},
"elastic_agent": {
"id": "a0570906-16fc-4c38-821f-7c3aa6ed04bb",
"id": "1fa7cf0a-419d-4967-a86b-696c132d365d",
"snapshot": false,
"version": "8.12.0"
"version": "8.19.0"
},
"event": {
"agent_id_status": "verified",
"dataset": "tenable_io.plugin",
"ingested": "2024-04-02T09:13:52Z",
"ingested": "2026-07-27T09:29:35Z",
"kind": "state",
"original": "{\"attributes\":{\"cpe\":[\"p-cpe:/a:fedoraproject:fedora:kernel-source\",\"cpe:/o:fedoraproject:fedora_core:1\",\"p-cpe:/a:fedoraproject:fedora:kernel-BOOT\",\"p-cpe:/a:fedoraproject:fedora:kernel-debuginfo\",\"p-cpe:/a:fedoraproject:fedora:kernel\",\"p-cpe:/a:fedoraproject:fedora:kernel-doc\",\"p-cpe:/a:fedoraproject:fedora:kernel-smp\"],\"cve\":[\"CVE-2003-0984\"],\"cvss3_base_score\":0,\"cvss3_temporal_score\":0,\"cvss_base_score\":4.6,\"cvss_temporal_score\":0,\"cvss_vector\":{\"AccessComplexity\":\"Low\",\"AccessVector\":\"Local-access\",\"Authentication\":\"None required\",\"Availability-Impact\":\"Partial\",\"Confidentiality-Impact\":\"Partial\",\"Integrity-Impact\":\"Partial\",\"raw\":\"AV:L/AC:L/Au:N/C:P/I:P/A:P\"},\"default_account\":false,\"description\":\"Various RTC drivers had the potential to leak...\",\"exploit_available\":false,\"exploit_framework_canvas\":false,\"exploit_framework_core\":false,\"exploit_framework_d2_elliot\":false,\"exploit_framework_exploithub\":false,\"exploit_framework_metasploit\":false,\"exploited_by_malware\":false,\"exploited_by_nessus\":false,\"has_patch\":true,\"in_the_news\":false,\"malware\":false,\"patch_publication_date\":\"2004-01-07T00:00:00Z\",\"plugin_modification_date\":\"2018-07-19T00:00:00Z\",\"plugin_publication_date\":\"2004-07-23T00:00:00Z\",\"plugin_type\":\"local\",\"plugin_version\":\"1.17\",\"risk_factor\":\"Medium\",\"see_also\":[\"http://example.com/u?07bc9e7f\"],\"solution\":\"Update the affected packages.\",\"synopsis\":\"The remote Fedora Core host is missing a security update.\",\"unsupported_by_vendor\":false,\"vpr\":{\"drivers\":{\"age_of_vuln\":{\"lower_bound\":366,\"upper_bound\":730},\"cvss3_impact_score\":5.9,\"cvss_impact_score_predicted\":false,\"exploit_code_maturity\":\"UNPROVEN\",\"product_coverage\":\"LOW\",\"threat_intensity_last28\":\"VERY_LOW\",\"threat_recency\":{\"lower_bound\":366,\"upper_bound\":730},\"threat_sources_last28\":[\"No recorded events\"]},\"score\":5.5,\"updated\":\"2018-07-19T00:00:00Z\"},\"xref\":[\"FEDORA:2003-047\"],\"xrefs\":[{\"id\":\"2003-047\",\"type\":\"FEDORA\"}]},\"id\":13670,\"name\":\"Fedora Core 1 : kernel-2.4.22-1.2140.nptl (2003-047)\"}",
"type": [
Expand Down Expand Up @@ -159,4 +159,4 @@
"temporal": 0
}
}
}
}
Loading
Loading