Skip to content
Open
Show file tree
Hide file tree
Changes from 2 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion packages/tenable_io/_dev/build/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ The Tenable Vulnerability Management integration collects logs for five types of

**Vulnerability** is used to retrieve all vulnerabilities on each asset, including the vulnerability state. See more details in the API documentation [here](https://developer.tenable.com/reference/exports-vulns-request-export).

**Scan** is used to retrieve details about existing scans and scan details, including scan statuses, assigned targets, and more. See more details in the API documentation for [Scan](https://developer.tenable.com/reference/scans-list) and [Scan Details](https://developer.tenable.com/reference/was-v2-scans-details).
**Scan** is used to retrieve details about existing scans and scan details, including scan statuses, assigned targets, and more. See more details in the API documentation for [Scan](https://developer.tenable.com/reference/scans-list) and [Scan Details](https://developer.tenable.com/reference/scans-details).

## Compatibility

Expand Down
12 changes: 4 additions & 8 deletions packages/tenable_io/_dev/deploy/docker/files/config.yml
Original file line number Diff line number Diff line change
Expand Up @@ -71,22 +71,18 @@ rules:
{"id":226,"name":"Targeted Scans","type":"custom","custom":1,"unread_count":0,"default_tag":0}
]
}
- path: /was/v2/scans/195
- path: /scans/195
methods: ["GET"]
responses:
- status_code: 200
body: |
{
"scan_id":"195","user_id":"53e1d711-f18f-4a75-a86e-1c47bccff1b7","config_id":"a772daba-3d6d-412c-8ee0-3279b19650b2","target":"http://192.0.2.119","created_at":"2020-02-05T23:11:49.342Z","updated_at":"2020-02-05T23:22:15.510Z","requested_action":"start","status":"completed","metadata":{"queued_urls":0,"scan_status":"stopping","crawled_urls":1,"queued_pages":0,"audited_pages":1,"request_count":74,"response_time":0}
}
- path: /was/v2/scans/423
{"info":{"owner":"jdoe@contoso.com","name":"Client Discovery","no_target":false,"folder_id":226,"control":true,"user_permissions":128,"schedule_uuid":"11c56dea-as5f-65ce-ad45-9978045df65ecade45b6e3a76871","edit_allowed":true,"scanner_name":null,"policy":null,"shared":true,"object_id":195,"tag_targets":[],"hostcount":1,"uuid":"a456ef1c-cbd4-ad41-f654-119b766ff61f","status":"completed","scan_type":"remote","targets":"192.0.2.57","alt_targets_used":false,"pci-can-upload":false,"scan_start":1683282785,"timestamp":1683283158,"is_archived":false,"scan_end":1683283158,"haskb":true,"hasaudittrail":true,"scanner_start":null,"scanner_end":null,"acls":[{"permissions":128,"owner":1,"display_name":"jdoe@contoso.com","name":"jdoe@contoso.com","id":1,"type":"user"}]},"history":[{"history_id":1000195,"owner_id":1,"creation_date":1683282785,"last_modification_date":1683283158,"uuid":"a456ef1c-cbd4-ad41-f654-119b766ff61f","type":"remote","status":"completed","scheduler":0,"alt_targets_used":false,"is_archived":false}],"hosts":[{"asset_id":5,"host_id":5,"hostname":"192.0.2.57","progress":"100-100/200-200","scanprogresscurrent":100,"scanprogresstotal":100,"numchecksconsidered":100,"totalchecksconsidered":100,"severitycount":{"item":[{"count":156,"severitylevel":0},{"count":1,"severitylevel":1},{"count":6,"severitylevel":2},{"count":3,"severitylevel":3},{"count":0,"severitylevel":4}]},"severity":166,"score":3766,"info":156,"low":1,"medium":6,"high":3,"critical":0,"host_index":0}],"vulnerabilities":[{"count":3,"plugin_id":34220,"plugin_name":"Netstat Portscanner (WMI)","severity":0,"plugin_family":"Port scanners","vuln_index":1}]}
- path: /scans/423
methods: ["GET"]
responses:
- status_code: 200
body: |
{
"scan_id":"423","user_id":"53e1d711-f18f-4a75-a86e-1c47bccff1b7","config_id":"a772daba-3d6d-412c-8ee0-3279b19650b2","target":"http://192.0.2.119","created_at":"2020-02-05T23:11:49.342Z","updated_at":"2020-02-05T23:22:15.510Z","requested_action":"start","status":"completed","metadata":{"queued_urls":0,"scan_status":"stopping","crawled_urls":1,"queued_pages":0,"audited_pages":1,"request_count":74,"response_time":0}
}
{"info":{"owner":"jdoe@contoso.com","name":"Client Vulnerabiltiy Scan Group B","no_target":false,"folder_id":227,"control":true,"user_permissions":128,"schedule_uuid":"1d63c64e-a5d1-df57-0ecf-9f0e288d8a45fe84bcd54e39daaf","edit_allowed":true,"scanner_name":null,"policy":null,"shared":true,"object_id":423,"tag_targets":[],"hostcount":1,"uuid":"a2389003-fec1-a45d-a45d-aece258c4133","status":"completed","scan_type":"remote","targets":"192.0.2.0/24","alt_targets_used":false,"pci-can-upload":false,"scan_start":1683043551,"timestamp":1683049400,"is_archived":false,"scan_end":1683049400,"haskb":true,"hasaudittrail":true,"scanner_start":null,"scanner_end":null,"acls":[{"permissions":128,"owner":1,"display_name":"jdoe@contoso.com","name":"jdoe@contoso.com","id":1,"type":"user"}]},"history":[{"history_id":1000423,"owner_id":1,"creation_date":1683043551,"last_modification_date":1683049400,"uuid":"a2389003-fec1-a45d-a45d-aece258c4133","type":"remote","status":"completed","scheduler":0,"alt_targets_used":false,"is_archived":false}],"hosts":[{"asset_id":3,"host_id":3,"hostname":"192.0.2.57","progress":"100-100/200-200","scanprogresscurrent":100,"scanprogresstotal":100,"numchecksconsidered":100,"totalchecksconsidered":100,"severitycount":{"item":[{"count":52,"severitylevel":0},{"count":11,"severitylevel":1},{"count":100,"severitylevel":2},{"count":58,"severitylevel":3},{"count":32,"severitylevel":4}]},"severity":253,"score":388162,"info":52,"low":11,"medium":100,"high":58,"critical":32,"host_index":0}],"vulnerabilities":[{"count":65,"plugin_id":34252,"plugin_name":"Microsoft Windows Remote Listeners Enumeration (WMI)","severity":0,"plugin_family":"Windows","vuln_index":1}]}
- path: /audit-log/v1/events
methods: ["GET"]
query_params:
Expand Down
5 changes: 5 additions & 0 deletions packages/tenable_io/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "4.13.0"
changes:
- description: Replace the scan details endpoint with GET /scans/{id} and remap the scan_details fields to the standard VM scan-details schema.
type: bugfix

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changelog entry is marked as type: bugfix under 4.13.0 (minor), but this change removes the published WAS scan_details.* fields and replaces them with the VM schema. Since it introduces a breaking schema change, it should be classified as a breaking-change and released as a major version.

If it's truly a bugfix, it should be a patch release (e.g., 4.12.1). As it stands, 4.13.0 with type: bugfix is inconsistent.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is not a breaking change since the previous code never worked. However, yes, this should bump patch.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I just thought it is a change it worths a minor version bump because of the size of the change. If you both think it should be a patch version despite the changes it includes that's ok for me.

link: https://github.com/elastic/integrations/pull/20347
- version: "4.12.0"
changes:
- description: Allow user configuration of maximum number of CEL executions for the asset, audit, plugin, and scan data streams.
Expand Down
91 changes: 38 additions & 53 deletions packages/tenable_io/data_stream/asset/sample_event.json
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
{
"@timestamp": "2018-12-31T22:27:58.599Z",
"agent": {
"ephemeral_id": "f945f2c2-fbaf-4b93-b6ca-7d51e6a0706d",
"id": "a0570906-16fc-4c38-821f-7c3aa6ed04bb",
"name": "docker-fleet-agent",
"ephemeral_id": "e923234c-5974-4b16-9bcb-8a239b43daf3",
"id": "936d2df1-19df-44ad-a3bb-57f1db8147c9",
"name": "elastic-agent-10653",
"type": "filebeat",
"version": "8.12.0"
"version": "9.4.3"
},
"cloud": {
"availability_zone": "12",
Expand All @@ -18,34 +18,33 @@
},
"data_stream": {
"dataset": "tenable_io.asset",
"namespace": "ep",
"namespace": "37407",
"type": "logs"
},
"ecs": {
"version": "8.11.0"
},
"elastic_agent": {
"id": "a0570906-16fc-4c38-821f-7c3aa6ed04bb",
"id": "936d2df1-19df-44ad-a3bb-57f1db8147c9",
"snapshot": false,
"version": "8.12.0"
"version": "9.4.3"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please regenerate the sample events with a 8.19.0 stack so that they match the behaviour of the stated minimum version. This will revert the scalar to array changes that we are seeing in the samples, for example tenable_io.asset.fqdns which becomes a scalar in this PR, but which 8.19.0 would render as an array.

},
"event": {
"agent_id_status": "verified",
"category": [
"host"
],
"dataset": "tenable_io.asset",
"ingested": "2024-04-02T09:13:00Z",
"ingested": "2026-07-24T08:46:22Z",
"kind": "state",
"module": "tenable_io",
"original": "{\"acr_score\":\"3\",\"agent_names\":[],\"agent_uuid\":\"22\",\"aws_availability_zone\":null,\"aws_ec2_instance_ami_id\":\"12\",\"aws_ec2_instance_group_name\":null,\"aws_ec2_instance_id\":\"12\",\"aws_ec2_instance_state_name\":null,\"aws_ec2_instance_type\":null,\"aws_ec2_name\":null,\"aws_ec2_product_code\":null,\"aws_owner_id\":\"44\",\"aws_region\":null,\"aws_subnet_id\":null,\"aws_vpc_id\":null,\"azure_resource_id\":\"12\",\"azure_vm_id\":\"12\",\"bigfix_asset_id\":null,\"bios_uuid\":\"33\",\"created_at\":\"2017-12-31T20:40:44.535Z\",\"deleted_at\":\"2017-12-31T20:40:44.535Z\",\"deleted_by\":\"user\",\"exposure_score\":\"721\",\"first_scan_time\":\"2017-12-31T20:40:23.447Z\",\"first_seen\":\"2017-12-31T20:40:23.447Z\",\"fqdns\":[\"example.com\"],\"gcp_instance_id\":\"12\",\"gcp_project_id\":\"12\",\"gcp_zone\":\"12\",\"has_agent\":false,\"has_plugin_results\":true,\"hostnames\":[],\"id\":\"95c2725c-7298-4a44-8a1d-63131ca3f01f\",\"installed_software\":[\"cpe:/a:test:xyz:12.8\",\"cpe:/a:test:abc:7.7.3\",\"cpe:/a:test:pqr:6.9\",\"cpe:/a:test:xyz\"],\"ipv4s\":[\"89.160.20.112\"],\"ipv6s\":[],\"last_authenticated_scan_date\":\"2017-12-31T20:40:44.535Z\",\"last_licensed_scan_date\":\"2018-12-31T22:27:52.869Z\",\"last_scan_id\":\"00283024-afee-44ea-b467-db5a6ed9fd50ab8f7ecb158c480e\",\"last_scan_time\":\"2018-03-31T22:27:52.869Z\",\"last_schedule_id\":\"72284901-7c68-42b2-a0c4-c1e75568849df60557ee0e264228\",\"last_seen\":\"2018-12-31T22:27:52.869Z\",\"mac_addresses\":[],\"manufacturer_tpm_ids\":[],\"mcafee_epo_agent_guid\":null,\"mcafee_epo_guid\":null,\"netbios_names\":[],\"network_interfaces\":[{\"fqdns\":[\"example.com\"],\"ipv4s\":[\"89.160.20.112\",\"81.2.69.144\"],\"ipv6s\":[\"2a02:cf40::\"],\"mac_addresses\":[\"00-00-5E-00-53-00\",\"00-00-5E-00-53-FF\"],\"name\":\"test.0.1234\"}],\"operating_systems\":[],\"qualys_asset_ids\":[],\"qualys_host_ids\":[],\"servicenow_sysid\":null,\"sources\":[{\"first_seen\":\"2017-12-31T20:40:23.447Z\",\"last_seen\":\"2018-12-31T22:27:52.869Z\",\"name\":\"TEST_SCAN\"}],\"ssh_fingerprints\":[],\"symantec_ep_hardware_keys\":[],\"system_types\":[],\"tags\":[{\"added_at\":\"2018-12-31T14:53:13.817Z\",\"added_by\":\"ac2e7ef6-fac9-47bf-9170-617331322885\",\"key\":\"Geographic Area\",\"uuid\":\"47e7f5f6-1013-4401-a705-479bfadc7826\",\"value\":\"APAC\"}],\"terminated_at\":\"2017-12-31T20:40:44.535Z\",\"terminated_by\":\"user\",\"updated_at\":\"2018-12-31T22:27:58.599Z\"}",
"type": [
"info"
]
},
"host": {
"domain": [
"example.com"
],
"domain": "example.com",
"id": "95c2725c-7298-4a44-8a1d-63131ca3f01f",
"ip": [
"89.160.20.112"
Expand Down Expand Up @@ -96,9 +95,7 @@
"exposure_score": 721,
"first_scan_time": "2017-12-31T20:40:23.447Z",
"first_seen": "2017-12-31T20:40:23.447Z",
"fqdns": [
"example.com"
],
"fqdns": "example.com",
"gcp": {
"instance_id": "12",
"project_id": "12",
Expand All @@ -113,53 +110,41 @@
"cpe:/a:test:pqr:6.9",
"cpe:/a:test:xyz"
],
"ipv4s": [
"89.160.20.112"
],
"ipv4s": "89.160.20.112",
"last_authenticated_scan_date": "2017-12-31T20:40:44.535Z",
"last_licensed_scan_date": "2018-12-31T22:27:52.869Z",
"last_scan_id": "00283024-afee-44ea-b467-db5a6ed9fd50ab8f7ecb158c480e",
"last_scan_time": "2018-03-31T22:27:52.869Z",
"last_schedule_id": "72284901-7c68-42b2-a0c4-c1e75568849df60557ee0e264228",
"last_seen": "2018-12-31T22:27:52.869Z",
"network_interfaces": [
{
"fqdns": [
"example.com"
],
"ipv4s": [
"89.160.20.112",
"81.2.69.144"
],
"ipv6s": [
"2a02:cf40::"
],
"mac_addresses": [
"00-00-5E-00-53-00",
"00-00-5E-00-53-FF"
],
"name": "test.0.1234"
}
],
"sources": [
{
"first_seen": "2017-12-31T20:40:23.447Z",
"last_seen": "2018-12-31T22:27:52.869Z",
"name": "TEST_SCAN"
}
],
"tags": [
{
"added_at": "2018-12-31T14:53:13.817Z",
"added_by": "ac2e7ef6-fac9-47bf-9170-617331322885",
"key": "Geographic Area",
"uuid": "47e7f5f6-1013-4401-a705-479bfadc7826",
"value": "APAC"
}
],
"network_interfaces": {
"fqdns": "example.com",
"ipv4s": [
"89.160.20.112",
"81.2.69.144"
],
"ipv6s": "2a02:cf40::",
"mac_addresses": [
"00-00-5E-00-53-00",
"00-00-5E-00-53-FF"
],
"name": "test.0.1234"
},
"sources": {
"first_seen": "2017-12-31T20:40:23.447Z",
"last_seen": "2018-12-31T22:27:52.869Z",
"name": "TEST_SCAN"
},
"tags": {
"added_at": "2018-12-31T14:53:13.817Z",
"added_by": "ac2e7ef6-fac9-47bf-9170-617331322885",
"key": "Geographic Area",
"uuid": "47e7f5f6-1013-4401-a705-479bfadc7826",
"value": "APAC"
},
"terminated_at": "2017-12-31T20:40:44.535Z",
"terminated_by": "user",
"updated_at": "2018-12-31T22:27:58.599Z"
}
}
}
}
17 changes: 9 additions & 8 deletions packages/tenable_io/data_stream/audit/sample_event.json
Original file line number Diff line number Diff line change
@@ -1,24 +1,24 @@
{
"@timestamp": "2018-12-31T01:40:07.000Z",
"agent": {
"ephemeral_id": "2b353f6e-e21d-4e61-a426-9b582471c1fa",
"id": "1a70a431-df2f-4f16-9352-a30f75fb1df2",
"name": "elastic-agent-83695",
"ephemeral_id": "26e5e5a4-8afa-432a-9eef-014d12a84731",
"id": "0b77014c-7599-4d4e-8eed-2df2c0ae9d89",
"name": "elastic-agent-96263",
"type": "filebeat",
"version": "8.18.1"
"version": "9.4.3"
},
"data_stream": {
"dataset": "tenable_io.audit",
"namespace": "31446",
"namespace": "45929",
"type": "logs"
},
"ecs": {
"version": "8.11.0"
},
"elastic_agent": {
"id": "1a70a431-df2f-4f16-9352-a30f75fb1df2",
"id": "0b77014c-7599-4d4e-8eed-2df2c0ae9d89",
"snapshot": false,
"version": "8.18.1"
"version": "9.4.3"
},
"event": {
"action": "session-delete",
Expand All @@ -28,8 +28,9 @@
],
"dataset": "tenable_io.audit",
"id": "eaac53481de04f67bc7eeea07d2fb0f5",
"ingested": "2025-06-03T16:34:47Z",
"ingested": "2026-07-24T08:47:03Z",
"kind": "event",
"module": "tenable_io",
"original": "{\"action\":\"session.delete\",\"actor\":{\"id\":\"d2667922-5a27-4c4a-9207-f591fbdc9d23\",\"name\":\"user2@example.com\"},\"crud\":\"d\",\"description\":null,\"fields\":[{\"key\":\"message\",\"value\":\"session timeout\"}],\"id\":\"eaac53481de04f67bc7eeea07d2fb0f5\",\"is_anonymous\":null,\"is_failure\":false,\"received\":\"2018-12-31T01:40:07Z\",\"target\":{\"id\":\"12d024e\",\"name\":null,\"type\":\"Session\"}}",
"outcome": "success",
"type": [
Expand Down
Loading
Loading