Tagging in Tenable Products
This guide is a comprehensive reference for how tagging works across the Tenable product portfolio. Whether you are tagging assets in Tenable One Vulnerability Management, creating Asset Tags in Tenable Security Center, managing risk segments in Tenable One, organizing your external attack surface in Tenable One Attack Surface Management, or automating tag workflows via the API, this guide covers the concepts, procedures, and best practices you need.
Applies To
| Product |
Deployment |
Feature Name |
| Tenable One Vulnerability Management
|
Cloud (SaaS) |
Tags (Category:Value) |
| Tenable Security Center
|
On-premises |
Asset Tags (typed asset lists) |
| Tenable Security Center Director
|
On-premises |
Asset Tags (same as Tenable Security Center) |
| Tenable One
|
Cloud (SaaS) |
Business Context (sourced from Tenable One Vulnerability Management Tags) |
| Tenable Exposure Management
|
Cloud (SaaS, part of Tenable One) |
Tags (Tenable One, Tenable One Vulnerability Management, and External) |
| Tenable One Attack Surface Management
|
Cloud (SaaS) |
Tags (name + value type) |
Topics in This Guide
- Core Concepts — What a tag is, tag types (static vs. dynamic), re-evaluation timing, and product terminology comparison.
- Tags in Tenable One Vulnerability Management — Tag structure and limits, manual and automatic tags, creating a tag, tag rules, rule filters reference, and management procedures.
- Tag-Based Scanning — The two scan target modes, when to use each, the Empty Targets abort, and the nested tag rule limitation.
- Tags in Tenable Exposure Management — The three tag types in Tenable Exposure Management (Tenable One, Tenable One Vulnerability Management, and External), capability matrix, structure and limits, creating and managing tags, and usage in Exposure View Cards, Dashboards, Inventory, and role-based access control.
- Tags in Tenable One Attack Surface Management — Tenable One Attack Surface Management's name + value type tag model, creating and assigning tags, removing and deleting tags, use cases, and limitations.
- Tags in Tenable Security Center — Tenable Security Center's Asset Tag types (Static, DNS Name List, LDAP Query, Combination, Dynamic, Import), creating and viewing Asset Tags, Tenable One Synchronization, Tenable Security Center Director, and an Asset Tags vs. Tags comparison.
- Tagging via API — API endpoints and example request bodies for Tenable One Vulnerability Management, Tenable One, Tenable One Attack Surface Management, and Tenable Security Center (including Tenable Security Center Director).
- Cross-Product Tag Behavior — How Tenable One Vulnerability Management Tags flow into Tenable One and Exposure Management, Business Context in Tenable One, tag-scoped risk metrics, the Tags (v2) navigation, and the full cross-product capability summary table.
- Best Practices — Naming conventions, tag rule design, cross-product tagging strategy, and governance.
- Examples — Six worked tagging configurations covering common real-world use cases.
- Troubleshoot Tags — Why tags don't apply as expected (including the Excluded Assets list and the recalculation schedule), the Findings-filter and multi-tag-filter limitations, and pointers for scan-related tag issues.
- Frequently Asked Questions — Answers to common conceptual questions about tag behavior, limits, timing, and access control.
Quick Reference — Where to Create Tags
| Goal |
Create Tags In |
Topic |
| Tag cloud or hybrid assets by business context, environment, or compliance scope |
Tenable One Vulnerability Management
|
Tags in Tenable One Vulnerability Management
|
| Group and target on-premises assets for scanning and reporting |
Tenable Security Center
|
Tags in Tenable Security Center
|
| Scope a scan to a tagged set of assets |
Tenable One Vulnerability Management
|
Tag-Based Scanning
|
| Drive Business Context segments and Cyber Exposure Score in Tenable One |
Tenable One Vulnerability Management
|
Cross-Product Tag Behavior
|
| Scope Exposure View Cards or Dashboards in Tenable Exposure Management |
Tenable Exposure Management (Tenable One Tags) or Tenable One Vulnerability Management |
Tags in Tenable Exposure Management
|
| Classify external attack surface assets (domains, IPs, web apps) |
Tenable One Attack Surface Management
|
Tags in Tenable One Attack Surface Management
|
| Automate tag creation and assignment at scale |
Tenable API (Tenable One Vulnerability Management, Tenable One Attack Surface Management, or Tenable Security Center REST API) |
Tagging via API
|
| Diagnose why a tag isn't applying, filtering, or scanning as expected |
Tenable One Vulnerability Management
|
Troubleshoot Tags
|
Additional Resources