TOC & Recently Viewed

Recently Viewed Topics

Install a Nessus Agent on Windows

Before You Begin

Nessus Agents can be deployed with a standard Windows service such as Active Directory (AD), Systems Management Server (SMS), or other software delivery system for MSI packages.

On Windows 7 x64 Enterprise, Windows 8 Enterprise, and Windows Server 2012, you may be required to perform a reboot to complete installation.

Nessus Agents can be deployed and linked using the command line. For example:

msiexec /i NessusAgent-<version number>-x64.msi NESSUS_GROUPS="Agent Group Name" NESSUS_SERVER="" NESSUS_KEY=00abcd00000efgh11111i0k222lmopq3333st4455u66v777777w88xy9999zabc00 /qn

Note: The NESSUS_GROUPS parameter accepts group names. Quotations are necessary only when listing multiple groups, or one group with spaces in its name. See the following examples:

  • GroupName
  • "Group Name"
  • "Group, Another Group"

The following linking parameters are also available:


Get the Linking Key

  1. In Nessus Manager, in the top navigation bar, click Scans.

    The My Scans page appears.

  2. In the left navigation bar, click Agents.

    The Agents page appears.

  3. In the Linked Agents tab, click the setup instructions link.

    The Agent Setup Instructions dialog box appears.

  4. Record the host, port, and key values.
  5. Click Close.

Download Nessus Agent

From the Nessus Agents Download Page, download the Nessus Agent specific to your operating system.

Start Nessus Agent Installation

  1. Navigate to the folder where you downloaded the Nessus Agent installer.
  2. Next, double-click the file name to start the installation process.

Complete the Windows InstallShield Wizard

  1. First, the Welcome to the InstallShield Wizard for Nessus Agent dialog box appears. Select Next to continue.
  2. From the License Agreement window, read the terms of the Tenable, Inc. Nessus software license and subscription agreement.
  3. Select the I accept the terms of the license agreement radio button, and then select the Next button.
  4. On the Destination Folder screen, select the Next button to accept the default installation folder. Otherwise, select the Change button to install Nessus in a different folder.

    Note: During the next step, you will need the Agent Key values: Key, Server (host), and Groups.

  5. On the Configuration Options screen, enter the Agent Key values: Key, Server (host), and Groups, and then select Next.

    Agent Key Values

    Required Values

    • Key
    • Server (host)

    Optional Value

    • Groups (Existing Agent Group(s) that you want your Agent to be a member of)

      If you do not specify an Agent Group during the install process, you can later add your linked Agent to an Agent Group within the Nessus UI.

    Note: Your Agent Name will be the computer name where the agent is installed.

  6. On the Ready to Install the Program screen, select Install.
  7. If presented with a User Account Control message, select Yes to allow the Nessus Agent to be installed.
  8. When the InstallShield Wizard Complete screen appears, select Finish.

Note: If you attempt to clone an Agent and link it to Nessus Manager, a 409 error may appear. This is because another machine has been linked with the same uuid value in the HKLM/Software/Tenable/TAG file. To resolve this issue, replace the value in the HKLM/Software/Tenable/TAG file with a valid UUIDv4 value.

Verify Linked Agent.

  1. In Nessus Manager, in the top navigation bar, click Scans.

    The My Scans page appears.

  2. In the left navigation bar, click Agents.

    The Agents page appears, and the new Agent appears in the table.

Copyright 2017 Tenable, Inc. All rights reserved. Tenable Network Security, Nessus, SecurityCenter, SecurityCenter Continuous View and Log Correlation Engine are registered trademarks of Tenable, Inc.  Tenable,, Assure, and The Cyber Exposure Company are trademarks of Tenable, Inc.  All other products or services are trademarks of their respective owners.