Health Checks
The health check feature in Tenable Identity Exposure provides you with real-time visibility into the configuration of your domains and service accounts in one consolidated view, from which you can drill down to investigate any configuration anomalies leading to connectivity or other issues in your infrastructure. It verifies that everything is properly set up to ensure the smooth operation of Tenable Identity Exposure and gives you the ability to take quick and precise actions to remedy issues, as well as the confidence that your configuration settings are optimal to enable Tenable Identity Exposure to function efficiently.
Health checks are visible by default for administrative roles and by permission for certain user roles. You can also create Syslog or email alerts on each change in health check status.
Health Checks and DC Sync Attack Detection
Health checks provide valuable information about the status and usability of Tenable Identity Exposure services. It verifies the service account's capability to collect sensitive information like password hashes and DPAPI backup keys used for Privileged Analysis. In the health check report, Tenable attempts to collect sensitive data to determine if the service account has the Privileged Analysis feature properly configured, without actually collecting anything if this feature is not in use. To prevent detection of a DCSync attack during this process, Tenable automatically whitelists the provided service account for the DCSync Indicator of Attack.
Domain Status
Tenable Identity Exposure performs the following checks for each domain:
-
Authentication to the AD domain — LDAP settings and status, credentials, and SMB access
-
Domain reachability — Working connection to the dynamic RPC port, a reachable SMB server, a reachable domain controller IP address or FQDN, a working connection to the RPC port, a reachable LDAP server, and a reachable global catalog LDAP server.
-
Permissions — Ability to access AD domain data and collect privileged data.
-
Domain Linked to Relay — The domain is correctly associated to a relay service.
Platform Status
Tenable Identity Exposure performs the following checks on your platform configuration:
-
Running Relay service — Whether or not the Relay configuration is correct with troubleshooting tips.
-
Relay version consistency — Whether or not the Relay version is consistent with the Tenable Identity Exposure version.
-
Running AD data collector service — Whether or not the data collector service, broker, and collector bridge are operational to relay data to other services.
-
At the bottom-left corner of the Tenable Identity Exposure page, hover over the icon to see the global status of your infrastructure.
-
Click on the icon to open the Health Check page. Under the Domain Status or the Platform Status tab, you see either one of the following:
-
A message that all health checks passed
-
A list of warnings or issues with specific statuses:
The check succeeded and shows a normal result. The check failed and identifies an issue. The check failed but the issue does not prevent Tenable Identity Exposure from working correctly.
For example, the check for data collection will result in failure due to a misconfiguration of the Active Directory on the client end if the service account cannot collect privileged data. However, it is not a serious issue because you haven't activated the Privileged Analysis feature on this domain in Tenable Identity Exposure, hence the warning. But if you activate Privileged Analysis, the check will immediately fail.
The check shows an unknown result because a dependent check failed. For example, the check for network reachability cannot proceed if the check for authentication failed.
-
-
Above the list of health checks on the right, click the toggle Show successful checks to enabled to list all the checks that Tenable Identity Exposure performed with the following information:
-
Health check name
-
Status (pass, fail, fail but non-blocking, or unknown)
-
Impacted domain and its associated forest (for domain status checks only)
-
Time of the last check performed
-
How long the check has remained in this status
-
-
Although it performs health checks on a regular basis, Tenable Identity Exposure does not update the page with the results in real time. Click on to refresh the list of results.
-
Above the list of health checks on the right, click on n/n health checks or n/n domains (for domain status only).
The Health Checks or Forests and Domains pane opens.
-
Select the health check types or forests/domains (if applicable) and click on Filter on selection.
-
In the list of health checks, click on a health check name or the blue arrow () at the end of the line.
The Details pane opens and shows a description of the check and a list of relevant details.Health Check Name Type Description of Check Reasons Domain Reachability Domain Ability to establish a connection with the AD domain -
IP-UNREACHABLE R-LDAP-GLOBAL-CATALOG-UNREACHABLE
-
LDAP-SERVER-UNREACHABLE
-
SMB-SERVER-UNREACHABLE
-
DYNAMIC-RPC-CONNECTION-NOT-WORKING
-
RPC-CONNECTION-NOT-WORKING
Authentication to the AD Domain Domain Ability to authenticate to the AD domain -
INCORRECT-CREDENTIALS
-
LDAP-SERVER-BUSY
-
LDAP-SERVER-UNAVAILABLE
-
LDAP-SERVER-ACCESS-DENIED
-
SMB-SERVER-ACCESS-DENIED
Permissions to Collect the AD Domain Data Domain Ability to collect the AD domain data -
MISSING-PERMISSIONS-PRIVILEGED-DATA
Permissions to Access the AD Containers Domain Ability to can access the AD containers -
MISSING-PERMISSIONS-DELETED-OBJECTS-ACCESS
-
MISSING-PERMISSIONS-PASSWORD-SETTINGS-ACCESS
Domain Linked to Relay Domain The domain is linked to a Relay -
LINKED-TO-RELAY-DOWN
Relay Service Up Platform The Relay is working as expected -
RELAY-DOWN
Relay Service Version Platform The Relay version is aligned with the product -
VERSION-MISMATCH
AD Data Collector Up Platform The AD data collector is working as expected -
DATA-COLLECTOR-SERVICE-DOWN
-
DATA-COLLECTOR-BRIDGE-DOWN
-
BROKER-DOWN
-
-
Click the arrow at the end of the detail line to expand it and show more information about the result.
By default, Tenable Identity Exposure shows the health check status icon at the bottom-left corner of the screen.
-
In Tenable Identity Exposure, go to System in the left navigation bar and select the Configuration tab.
Alternatively, you can click on at the top-right corner of the Health Check page and select Configuration.
-
Under Application Services, select Health Check.
-
Click the toggle Show the Global Health Check Status to disabled.
Tenable Identity Exposure hides the health check icon at the bottom-left corner of the screen.
-
In Tenable Identity Exposure, go to Accounts in the left navigation bar and select the Roles Management tab.
-
In the list of roles, select the user role and click on at the end of the line.
The Edit a role pane opens.
-
Select the System configuration entities tab.
-
Select the Health Check entity and click the permission toggle from Unauthorized to Granted.
-
Click Apply and close.
For more information about permissions, see Set Permissions for a Role.
-
In Tenable Identity Exposure, go to System in the left navigation bar and select the Configuration tab.
Alternatively, you can click on at the top-right corner of the Health Check page and select Alerts.
-
Under Alerting Engine, select Syslog or Email.
-
Click Add a Syslog alert or Add an email alert.
A new pane opens. For the complete procedure, see Alerts.
-
Under Alert Parameters, in the Trigger the Alert box, select On health check status change from the drop-down menu.
-
Click the arrow in the Health Checks box to select the health check type to trigger an alert, and click Filter on selection.
-
Click Add.