Welcome to Tenable for IBM QRadar SIEM
Last Updated: August 26, 2026
This document provides information and steps for integrating Tenable One Vulnerability Management, Tenable One Identity Exposure, Tenable One OT Exposure, and Tenable Security Center applications with IBM QRadar Security Information and Event Management (SIEM).
IBM QRadar SIEM (QRadar) is a network security management platform that provides situational awareness and compliance support. It collects, processes, aggregates, and stores network data in real time. QRadar has a modular architecture that provides real-time visibility of your IT infrastructure that you can use for threat detection and prioritization. You can use the customized Tenable applications in QRadar. to obtain vulnerability summaries for Tenable One Vulnerability Management, Tenable One Identity Exposure, Tenable One OT Exposure, or Tenable Security Center that correspond to the source IP address for each offense.
How It Works
-
QRadar VM:
-
Get vulnerabilities from Tenable and import them into QVM.
-
-
Tenable App for QRadar:
-
For a given machine on an offense:
-
Get a summary of vulnerabilities.
-
Initiate a scan with a right-click.
-
Scan a host during an investigation.
-
-
Parse Tenable One OT Exposure events with the Embedded Device Support Module (DSM).
-
Parse Tenable Exposure Management events with the Embedded Device Support Module (DSM).
-
For additional information about IBM QRadar SIEM, refer to the IBM QRadar SIEM website.