Database Integration

To configure database integration:

  1. Log in to your Tenable user interface.

  2. Click Scans.

    The My Scans page appears.

  3. Click + New Scan.

    The Select a Scan Template page appears.

  4. Select a scan template. For demonstration, the Advanced Network Scan template is used.

    The scan configuration page appears.

  5. In the Name box, type a name for the scan.
  6. In the Targets box, type an IP address, hostname, or range of IP addresses.
  7. (Optional) Add a description, folder location, scanner location, and specify target groups.

  8. Click the Credentials tab.

    The Credentials pane appears.

  9. Click the Database option.

    The Database options appear.

  10. From the Database Type drop-down, select Oracle, DB2, MongoDB, PostgreSQL, MySQL, or SQL Server.

  11. From the Auth Type drop-down, select QiAnXin.

    The QiAnXin field options appear.

  12. Configure each field for the Database authentication.

    Option Description Required

    QiAnXin Host

    The IP address or URL for the QiAnXin host.

    yes

    QiAnXin Port

    The port on which the QiAnXin API communicates. By default, Tenable uses 443.

    yes

    QiAnXin API Client ID

    The Client ID for the embedded account application created in QiAnXin PAM

    yes

    QiAnXin API Secret ID The Secret ID for the embedded account application created in QiAnXin PAM

    yes

    Username The username to log in to the hosts you want to scan. yes
    Host IP Specify the host IP of the asset containing the account to use. If not specified, the scan target IP is used. no
    Platform

    Specify the platform (based on asset type) of the asset containing the account to use. If not specified, a default target is used based on credential type (for example, for Windows credentials, the default is WINDOWS). Possible values:

    • ACTIVE_DIRECTORY — Windows Domain Account

    • WINDOWS — Windows Local Account

    • LINUX — Linux Account

    • SQL_SERVER — SQL Server Database

    • ORACLE — Oracle Database

    • MYSQL — MySQL Database

    • DB2 — DB2 Database

    • HP_UNIX — HP Unix

    • SOLARIS — Solaris

    • OPENLDAP — OpenLDAP

    • POSTGRESQL — PostgreSQL

    no
    Region ID Specify the region ID of the asset containing the account to use. Only if using multiple regions
    Use SSL When enabled, Tenable uses SSL for secure communication. This is enabled by default.

    no

    Verify SSL Certificate

    When enabled, Tenable verifies that the SSL Certificate on the server is signed by a trusted CA.

    no

  1. Click Save.