Automated Pull from Cloud Storage in Tenable One Open Connector

The following is not supported in Tenable FedRAMP Moderate environments. For more information, see the Tenable FedRAMP Product Offering.

You can use the Tenable One Open Connector to automate the discovery and import of assets and finding data into Tenable Exposure Management. This capability replaces manual file uploads with continuous, scheduled syncs from remote storage environments.

By connecting directly to cloud providers, the Tenable One Open Connector ensures your data reflects the current state of your environment without manual intervention.

Configure Automated Pull from Cloud Storage

Remap Columns

The Remap Columns option allows you to revise field mappings or uniqueness criteria for your existing S3 data source. Modifying these settings while using Incremental Fetch may require a data baseline reset to ensure platform integrity.

To remap columns:

  1. On the Connectors page, click the Tenable One Open Connector instance you want to edit.
  2. At the bottom right of the screen, click Remap Columns.

    The Map Attributes page appears.

  3. Remap the source columns to the platform attributes as needed.
  4. Click Next.

    The Data Aggregation and Uniqueness page appears.

  5. On the Data Aggregation and Uniqueness page, identify and apply any required changes to your unique identifiers.
  6. Click Save & Sync.
  7. Identify if a Data Sync Conflict alert appears.

    Important: If you use Incremental Fetch and modify field mappings or unique identifiers, you must force a baseline reset. Changing these IDs prevents Tenable Exposure Management from recognizing existing records and can cause data duplication.

  8. To proceed, select the Run next upload as "Override File (Full Fetch)" check box. After this initial full fetch, Tenable Exposure Management automatically resumes incremental syncs using your selected mode for all future updates.
  9. Click Update & Sync.

Note: If you need to switch your data source from manual upload to automated pulling, see Manage Data Sources and Update Modes in Tenable One Open Connector.

Tenable One Open Connector Data in Tenable Exposure Management

Locate Connector Assets in Tenable Exposure Management

As the connector discovers assets, Tenable Exposure Management ingests those devices for reporting.

To view assets by connector:

  1. In Tenable Exposure Management, navigate to the Assets page.

  2. In the Filters section, under Custom, click the connector name for which you want to view assets.

    The asset list updates to show only assets from the selected connector.

  3. Click on any asset to view Asset Details.

Locate Connector Weaknesses in Tenable Exposure Management

As the connector discovers weaknesses, Tenable Exposure Management ingests those weaknesses for reporting.

To view weaknesses by connector: 

  1. In Tenable Exposure Management, navigate to the Weaknesses page.

  2. In the Filters section, under Custom, click the connector name for which you want to view weaknesses.

    The weaknesses list updates to show only weaknesses from the selected connector.

  3. Click on any weakness to view Weakness Details.

Locate Connector Findings in Tenable Exposure Management

As the connector discovers individual findings, Tenable Exposure Management ingests those findings for reporting.

To view findings by connector:

  1. In Tenable Exposure Management, navigate to the Findings page.

  2. In the Filters section, under Custom, click the connector name for which you want to view findings

    The findings list updates to show only assets from the selected connector.

  3. Click on any asset to view Finding Details.

Expected Post-Sync Behavior

After a successful synchronization, Tenable Exposure Management performs the following actions based on your selected sync mode:

  • Full fetch (override): Replaces all existing asset records and findings for the connector instance with the content of the new file. Tenable Exposure Management archives assets and marks findings as Fixed if they are missing from the latest upload.

  • Incremental fetch (update): Updates the existing baseline with only the new or changed data found in the file. Tenable Exposure Management reconciles missing assets or findings based on your selected delta mode (Additive Only, Strict Inventory, or Dynamic Remediation). If you upload an asset-only inventory file, the platform defaults to Stable Inventory Mode automatically.

  • Uniqueness and mapping changes: Applies updated uniqueness criteria or field mappings only after a mandatory Full Fetch baseline reset. Tenable Exposure Management does not retroactively modify data already ingested with previous uniqueness logic.

  • Data cleanup: Disregards previous values for any non-mandatory fields removed from the latest mapping.

Manual vs. Automated Data Validation and Synchronization

Tenable Exposure Management uses a combination of scheduled tasks and real-time triggers to ensure your ingested data remains current. Tenable Exposure Management applies the following logic to manage your S3 data pipeline:

  • Automated daily synchronization: Tenable Exposure Management performs an automated synchronization according to the Connector Scheduling setup.

  • Manual validation: To bypass the daily schedule and identify changes immediately, use the Test Connectivity feature to validate data manually.

Validate Data Manually

If you update a file in your S3 bucket and require an immediate synchronization, perform the following steps:

  1. On the Connectors page, click the Tenable One Open Connector you want to update.
  2. On the Connector Details page, click Test Connectivity.

    Tenable Exposure Management runs a validation check against the source file in your S3 bucket. Tenable Exposure Management identifies any structural or content changes made on the vendor side.

  3. Click Next.

    If the Tenable One Open Connector detects a change, a notification appears in the interface to alert you that the file has changed.

  4. Proceed with the process as usual. Tenable Exposure Management automatically ingests the updated file with the most recent data.

Detailed Data Flow Logic

If the file in your S3 bucket changes between auto-discovery and the final synchronization, Tenable Exposure Management applies the following logic:

  • New file detected: If a newer file exists, Tenable Exposure Management continues the current sync with the original file. The log alerts you that Tenable Exposure Management will pull the new file during the next sync.

  • File updated with non-mandatory columns changes: If the file is updated with new or removed non-mandatory columns, Tenable Exposure Management continues the sync and alerts you in the log.

  • File updated with mandatory columns removed: If the update removes mandatory columns, the sync fails. You must update the mapping to proceed.

  • File deleted: If the file is removed from S3, the sync fails with a "File not found" message.

Synchronization Logic

The Tenable One Open Connector applies the following logic during automated cloud syncs:

  • File selection: If multiple files match the file pattern, Tenable Exposure Management selects the single file with the latest time stamp.

  • File override: In every successful pull, Tenable Exposure Management replaces the previous file for the specific connector ID.

  • No new file detected: Tenable Exposure Management compares the timestamp of available files against the last processed file. If no new file is found, Tenable Exposure Management skips the synchronization and displays the message "No new file detected".

  • Finding status: Tenable Exposure Management moves findings not included in the new file to the Fixed state.

  • Credentials or setup modification: If you change the credentials or remap a file, you must test the connectivity before you can save and sync the connector.

  • Full sync: In Full Fetch mode, Tenable Exposure Management archives assets and marks findings as Fixed if not present in the new file.
  • Incremental sync: Tenable Exposure Management reconciles missing data against the baseline based on your selected Delta mode.
  • Baseline Sync: Switching from Full to Incremental mode requires the next synchronization to run as a Full Fetch.

File Size and Log Requirements

Tenable Exposure Management enforces a 2 GB file size limit. If a file exceeds this limit, Tenable Exposure Management behaves as follows:

  • Initial setup: The error message “The file size exceeds the 2 GB limit” appears on the setup page and in the connector logs.

  • Secondary syncs: The error message appears in the connector logs only.

Connectivity Errors

If a sync or connectivity test fails, review the error messages to troubleshoot configuration issues.

Scenario Message
Authentication failure "Failed test 1 out of 2: the credentials are not correct."
Missing mandatory columns "File is missing mandatory columns and the data cannot be synced."
Empty file detected "Sync Failed: No Records Found."
File too large "The file size exceeds the 2 GB limit."