Tenable.ad Log Extension for QRadar
Overview
Tenable.ad features allow users to anticipate threats, detect breaches, and respond to incidents and attacks. Through its policies and alerts mechanism, Tenable.ad generates real-time alerts that are accurate, actionable, and customized for each network and its unique needs.
Tenable.ad reports these alerts to QRadar via Syslog. For each individual policy, users can decide whether an alert should be sent to QRadar via Syslog; this offers them maximum control over which information is being sent.
Installing the Tenable.ad Extension
In order to integrate Tenable.ad with your QRadar system, you need to download the Tenable.ad extension from the IBM X-Force Exchange and install it.
To download and install the extension:
- In the IBM QRadar console, open the Admin tab.
-
In the System Configuration section, click on Extension Management.
- In the Extension Management window, click Add and select the TenableotCustom_ext archive file.
-
Select the Install Immediately checkbox to install the extension immediately.
Before the extension is installed, a preview list of the content items appears.
Configuring a Tenable.ad Log Source
To configure Tenable.ad as a log source:
-
In the Data Sources section of the Admin tab, click on Log Sources.
-
In the Log Source window click on Add.
The Add a log source window opens.
- In the Log Source Type field, select Tenable.ad.
-
In the Log Source Extension field, select TenableadCustom_ext.
-
Fill in the additional fields as needed and click Save.
For information on how to send alerts to QRadar, see Sending Tenable.ad Alerts to QRadar.