Tenable One Open Connector FAQ
The following is not supported in Tenable FedRAMP Moderate environments. For more information, see the Tenable FedRAMP Product Offering.
The following are frequently asked questions regarding the Tenable One Open Connector.
What happens when I switch between static file uploads and automated pulls?
Tenable Exposure Management maintains your Data Update Mode (Full vs. Incremental) when transitioning between data sources. Tenable Exposure Management applies the following logic:
- Switching to Automated: If you transition from a manual upload to an automated pull, the platform retains your sync mode. If you were using Incremental Fetch, the first automated pull uses the previous manual "Full" sync as its baseline. Switching to automated Full Fetch triggers a Confirm Data Override warning.
- Switching to Static (Manual): If you switch back to manual uploads while in Incremental Fetch mode, your file must follow the existing incremental criteria established by the previous cloud storage sync.
What should I expect when switching between Full Fetch and Incremental Fetch modes?
Changing your sync mode triggers specific behaviors to protect data integrity:
- Switching from Full to Incremental: To establish a reliable starting point, Tenable Exposure Management performs the very next synchronization as a Full Fetch baseline. Subsequent syncs process only incremental changes.
- Switching from Incremental to Full: A Confirm Data Override alert appears. This mode replaces the entire dataset, which may reset historical trend lines and remediation metrics.
What happens if I change the unique identifiers or mappings while using Incremental Fetch?
Modifying uniqueness criteria or field mappings is incompatible with Incremental Fetch. These identifiers allow Tenable Exposure Management to recognize existing records. Changing them would cause data duplication. To save these changes, you must select the Run next upload as "Override File (Full Fetch)" check box to reset your data baseline.
What happens if I change the connector credentials?
Updating credentials (such as AWS Access Keys or Role ARNs) retains your Data Update Mode but re-initiates the configuration flow. You must complete the connectivity test, preview, mapping, and uniqueness steps again to ensure the new credentials can access the data.
Credential updates behave the same way for the other cloud providers:
- Azure Blob Storage: the Microsoft Entra ID service principal — tenant ID, client ID, and client secret.
- Google Cloud Storage (GCS): the service account key (JSON).
Credential updates behave the same way for a database data source:
- BigQuery (GCP): the service account key (JSON) and the GCP project identifier.
- Oracle: the host, port, user name, password, and the Service Name or SID value.
What happens if my sync fails with an "Incompatible File Content" error?
This error occurs if the structure of your new file does not align with your selected Incremental Fetch mode. For example, selecting a findings-based delta mode for an asset-only file will cause a failure. You must update either the file content or the sync mode to proceed.
What happens if an asset appears in the first file but is missing from later uploads?
The behavior depends on your Data Update Mode and selected reconciliation mode:
- Full Fetch: The platform archives the missing asset immediately.
- Incremental Fetch (Additive Only): The asset remains active subject to your Asset Retention policy.
- Incremental Fetch (Strict Inventory): The platform archives the missing asset immediately to maintain a clean inventory.
Which databases can the Tenable One Open Connector query?
The connector supports BigQuery (GCP) and Oracle. An Oracle connection requires the Tenable on-premises agent inside your network. A BigQuery (GCP) connection does not. For more information, see Automated Pull from Database in Tenable One Open Connector.
Does the connector run my SQL query on every sync?
Yes. Every sync runs your query again, and Tenable Exposure Management ingests the result. The connector compares no files between syncs and skips no syncs, so your database processes the query on every scheduled run. Set your schedule to match the cost and load that your database can absorb.
What happens if I change my SQL query?
You must run Test Connectivity and preview the result again before you can save the connector. Tenable Exposure Management runs your new query with a 10-row limit, revalidates your mapping against the returned columns, and suggests mappings based on your previous configuration. Map any column that your previous mapping no longer matches.
Why does my database sync fail with a flat table error?
Your query returned a nested or structured column, and Tenable Exposure Management supports only a single flat table. In BigQuery, examples include a RECORD, STRUCT, REPEATED, or native JSON column. In Oracle, examples include an object type, a collection type, REF CURSOR, or the native JSON type. To resolve the error, cast the column to a text value, or select its individual attributes as separate columns in your query.
Does the 2 GB file size limit apply to a database query result?
No. The 2 GB limit applies to file-based sources, such as a static file upload or a cloud storage pull. It does not apply to the result of a database query.
Can the connector write to my database?
No. The connector reads data only. It does not write, update, or delete records in your database.
How does Asset Retention work in the Tenable One Open Connector?
Tenable Exposure Management automatically removes assets once they exceed the Asset Retention period. The default is 460 days. You can customize this value in the connector settings.
| Source File State | Expected Retention Behavior |
|---|---|
| Source file includes a mapped Asset Last Observed At attribute. | The asset remains in the platform as long as the provided date, plus the retention days, is greater than the current date. |
| Source file does not include a timestamp. | The platform uses the time of the file upload or cloud storage pull as the Asset Last Observed At value. The retention period starts from that ingestion date. |