.png)
Tenable Integration Guide
Integrate Tenable vulnerability, asset, scan, and finding data with enterprise systems through REST APIs, asynchronous exports, and product-specific notifications.
Tenable integration options at a glance
Tenable primarily integrates through REST APIs for assets, findings, vulnerabilities, scans, tags, plugins, policies, users, and related resources. Its bulk export operations support asynchronous processing of large asset and vulnerability datasets by creating an export, polling its status, and retrieving result chunks. Product-specific notification or callback capabilities may exist, but a universal webhook stream is not confirmed and should be validated for the selected Tenable product. Tenable Vulnerability Management commonly authenticates with access and secret keys in the X-ApiKeys header. Martini can securely consume these APIs, orchestrate polling and exports, transform responses, and expose normalized APIs to downstream systems.
Common Tenable integration patterns
Common Tenable data objects used in integrations
Authentication and security considerations
API keys and permissions
Tenable Vulnerability Management commonly uses an access key and secret key in the X-ApiKeys request header. The associated Tenable user determines access to Assets, Findings, Scans, Tags, exports, and administrative resources.
Credential protection
Store Tenable credentials as protected Martini secrets. Do not place keys in workflow parameters, source-controlled mappings, logs, or error payloads. Rotate long-lived keys according to organizational policy.
Product-specific security
Authentication and authorization can vary across Tenable Vulnerability Management, Security Center, Tenable One, Web App Scanning, Cloud Security, and other products. Confirm the applicable product endpoint, API version, permissions, and credential model before deployment.
- Use separate least-privilege credentials for reporting, synchronization, scan orchestration, and administration.
- Protect Martini APIs that expose normalized Tenable data or accept scan requests.
- Keep regional and product-specific endpoints in environment configuration.
Operational considerations for Tenable integrations
Rate limits and pagination
Confirm applicable Tenable limits for the product and subscription. Use bounded concurrency, backoff for throttling responses, and complete pagination rather than assuming the first response contains all data.
Exports and checkpoints
For large datasets, create asynchronous exports, poll at a controlled interval, process chunks incrementally, and persist export identifiers and last successful chunks. Checkpoints should be restartable and isolated by tenant and resource type.
Idempotency and schema changes
Use stable identifiers or composite finding keys, tolerate repeated pages and chunks, and support reopened or fixed Finding states. Validate nullable fields, product-specific structures, severity values, and pagination or export formats.
Retries and testing
- Retry transient rate-limit and service failures with bounded backoff.
- Surface authentication, permission, invalid-resource, and malformed-response failures for operator action.
- Validate Scan and Policy scope and prevent unsafe concurrent scans.
- Test against the actual Tenable product, API version, permissions, regional endpoint, and representative data volumes.
Why use Martini instead of scripts or point-to-point integrations?
Orchestration instead of isolated scripts
Martini centralizes Tenable API calls, asynchronous export processing, pagination, transformations, business rules, and downstream delivery in maintainable workflows. This avoids duplicating authentication, retry, checkpoint, and error-handling logic across scripts.
Canonical data and reusable APIs
Martini can isolate product-specific Tenable schemas from target applications by mapping Assets, Findings, Scans, Tags, Plugins, and related resources into canonical models. It can also expose controlled APIs for normalized data or approved scan operations.
Operational reliability
- Schedule incremental synchronization and coordinate long-running exports.
- Apply idempotency, validation, routing, and controlled retries consistently.
- Use protected secrets and environment configuration across deployments.
- Monitor workflow execution and troubleshoot failures without creating separate point-to-point implementations.