Tags in Tenable Security Center

Asset Tag Overview

Tenable Security Center (on-premises) uses Asset Tags as its primary mechanism for grouping the assets it monitors — including vulnerability management, OT, and web application scanning data — so you can target them for scanning, filtering, and reporting. Some Asset Tag types are functionally similar to Tenable One Vulnerability Management Tags: Dynamic Asset Tags use rule-based condition statements that Tenable Security Center re-evaluates against scan results, and Combination Asset Tags build on existing Asset Tags using AND, OR, and NOT operators.

Key differences from Tenable One Vulnerability Management Tags:

  • Asset Tags are typed lists of assets, not structured Category:Value pairs.
  • Asset Tags apply only to assets. Other objects, such as scan policies, credentials, and queries, cannot be grouped by an Asset Tag.
  • Only Dynamic and Combination Asset Tags support rule-based or derived membership. The remaining types (Static, DNS Name List, LDAP Query, Import) are membership lists you populate directly.
Note: Tenable Security Center also has a separate, unrelated Labels feature — a free-form text descriptor you can attach to an asset, scan policy, credential, or query for lightweight filtering. Labels have no rule engine and are not shared across object types. For details, see Labels in the Tenable Security Center User Guide.

Asset Tag Types

Tenable Security Center supports Template-Based Asset Tags as well as seven custom Asset Tag types:

  • Template-Based — Pre-configured by Tenable and customizable for your environment. Templates update via the Tenable Security Center feed.
  • Static Asset Tags — A list of specific IP addresses, CIDR ranges, or IP ranges (up to 50,000 characters). Usable immediately after setup.
  • DNS Name List Asset Tags — A list of DNS hostnames.
  • LDAP Query Asset Tags — A dynamic list built from a query against a configured LDAP server, using search base and search string parameters.
  • Combination Asset Tags — A list built from existing Asset Tags using AND, OR, and NOT operators. Membership updates automatically when a source Asset Tag changes.
  • Dynamic Asset Tags — A list built from rule-based condition statements. Tenable Security Center refreshes membership using results from Tenable Security Center scans, and requires an initial discovery scan before it can populate.
  • Import Asset Tags — An Asset Tag reimported from a previously exported file.
Caution: DNS Name List and LDAP Query Asset Tags cannot target agent scans or agent synchronization jobs. If you need agent-based scanning or synchronization, use a Static or Dynamic Asset Tag instead.

Permissions and Sharing

Managing Asset Tags requires an Organizational User role with appropriate permissions. The Assets → Asset Tags page reflects only the Asset Tags you have permission to view.

Asset Tags can be shared with one or more users based on your organization's local security policy requirements. Asset Tag lists are calculated per repository — updating an Asset Tag in one repository does not affect other repositories.

Create an Asset Tag

Create an Asset Tag to group assets so you can target, filter, and report on them as a set.

Before You Begin

  • Confirm you have an Organizational User role with appropriate permissions.

  • Decide which Asset Tag type fits your use case: a Template-Based tag, or a custom Static, DNS Name List, LDAP Query, Combination, Dynamic, or Import tag.

  • If you are creating a Dynamic Asset Tag, confirm that Tenable Security Center has already run an initial discovery scan against the target assets.

To create an asset tag:

  1. Log in to Tenable Security Center.

  2. In the left navigation bar, click Assets → Asset Tags.

    The Asset Tags page appears.

  3. Click the Add button.

    The Asset Tag Templates page appears, with Template-Based options grouped under Common and custom types grouped under Other.

  4. Do one of the following:

    • To use a pre-configured template, select a template type in the Common section (use the Search box if needed), click the template row, review the details on the Add Asset Tag Template page, and click Add.

    • To build a custom Asset Tag, select a type in the Other section: Static, DNS Name List, LDAP Query, Combination, Dynamic, or Import.

  5. On the Add Asset Tag page, type a Name and, optionally, a Description, then complete the fields specific to the selected type — for example, IP addresses for a Static Asset Tag, or rule-based condition statements for a Dynamic Asset Tag.

  6. Click Submit.

    Tenable Security Center saves the Asset Tag and adds it to the Asset Tags list.

What To Do Next

Use the new Asset Tag as a scan target, or view its details as described in the next section.

View Asset Tag Details

To view asset tag details:

  1. On the Asset Tags page, right-click the target row, or select its checkbox and choose View from the action bar.

  2. Click View.

    The View Asset Tag page appears, showing a General section (Name, Description, Label, IP Addresses per Repository, Created, Modified, Owner, Group, and ID) and a Tenable Synchronization Data section (synchronization status with Tenable Lumin).

Note: The label field shown on the View Asset Tag page is the same free-form Labels feature described earlier in this topic, not part of the Asset Tag's typed definition.

Asset Tags and Tenable One Synchronization

By default, Asset Tags stay local to your Tenable Security Center instance. If your organization holds a Tenable Lumin or Tenable One license, you can optionally enable Tenable One Synchronization to send eligible Asset Tag and vulnerability data from Tenable Security Center into Tenable One Vulnerability Management, where it appears as tags — and from there can flow into Tenable One as Business Context using the same mechanism as native Tenable One Vulnerability Management Tags. See Cross-Product Tag Behavior for that downstream flow.

Tenable One Synchronization has the following scope and requirements:

  • Only IPv4 addresses within Static and Dynamic Asset Tags are eligible. DNS Name List, LDAP Query, Combination, and Import Asset Tags are not synchronized.
  • Requires a Tenable Lumin or Tenable One license and Tenable One Vulnerability Management API credentials (an Access Key and Secret Key) with Administrator permissions.
  • You cannot synchronize a Tenable Security Center Director instance. Only managed, standalone Tenable Security Center instances are supported.
  • Synchronized repositories must have unique names across instances, or the synchronization fails.
  • Assets that count toward your Tenable Security Center license also count toward your Tenable One Vulnerability Management license once synchronized.
  • Sending data to Tenable One Vulnerability Management does not remove it from Tenable Security Center — your original Asset Tags and scan data remain intact.
Note: The free-form Labels feature never synchronizes, regardless of whether Tenable One Synchronization is configured.

Removing or Deleting an Asset Tag

To delete an asset tag:

  1. On the Asset Tags page, right-click the target row, or select its checkbox and choose an action from the action bar.

  2. Click Delete.

    Tenable Security Center prompts you to confirm.

  3. Click Delete to confirm.

    Tenable Security Center removes the Asset Tag. Scans, policies, or dashboards that targeted the deleted Asset Tag no longer resolve that target.

Caution: Deleting an Asset Tag that is used as a scan target removes that target from any scan configured to use it. Coordinate deletions with scan and dashboard owners before proceeding.

Asset Tags vs. Tags — Comparison

Aspect Tenable Security Center Asset Tags Tenable One Vulnerability Management Tags
Structure Typed asset list (Static, DNS Name List, LDAP Query, Combination, Dynamic, Import, or Template-Based) Category:Value pair
Automation Dynamic and Combination types update automatically; the remaining types are manual lists Manual or rule-based (dynamic)
Applies to Assets only Assets only
Shared across users Yes — per local security policy Tag-level Can View / Can Edit permissions
Flows to Tenable One Partially — only via optional Tenable One Synchronization (IPv4 addresses in Static and Dynamic Asset Tags only, requires a Tenable Lumin or Tenable One license) Yes (as Business Context)
Maximum No documented limit per instance 100 categories; 100,000 values per category
Export Export and Import Asset Tag files CSV or JSON from Settings → Tagging
Permissions model Shared with specific users per local security policy Tag-level Can View / Can Edit permissions

Asset Tags in Tenable Security Center Director

Tenable Security Center Director is a multi-console management layer that provides a centralized view and control plane across multiple Tenable Security Center instances. Tenable Security Center Director is itself an on-premises deployment and shares the same Asset Tag functionality as a standard Tenable Security Center installation.

  • Asset Tags configured within Tenable Security Center Director itself are local to that Director instance and are not pushed down to managed Tenable Security Center consoles.
  • Asset Tags on individual managed Tenable Security Center consoles remain local to those consoles and do not aggregate up to Tenable Security Center Director.
  • You cannot enable Tenable One Synchronization on a Tenable Security Center Director instance itself. Individual managed Tenable Security Center instances can still be synchronized on their own.

If your organization uses Tenable Security Center Director to manage multiple Tenable Security Center deployments, maintain consistent Asset Tag naming and type conventions across all consoles manually. Because Asset Tags are not shared across consoles, a tag created in one managed Tenable Security Center instance is invisible to Tenable Security Center Director and to other managed Tenable Security Center instances.

Note: Tenable Security Center Director API access for Asset Tag management follows the same pattern as the Tenable Security Center REST API, targeting the Director host. See Tagging via API for details.

Additional Resources