Tenable Core + Tenable OT Security Sensor Information
The OT Security Sensor information page displays several information tiles related to your instance. This information allows you to monitor installation elements and view logs.
Parameters unique to your OT Security Sensor installation.
Note: Some items in this section may be hidden if you have insufficient permissions.
| Installation Parameter | Description |
|---|---|
| Service Status | The current status of your OT Security Sensor. Possible values are: running, stopping, stopped, starting, and failed. |
| Application Version | The version of OT Security Sensor currently running. |
| RPM Version | The version of OT Security Sensor that is currently installed on the system. |
| Sensor Identifier | The identification string of the OT Security Sensor you are running. |
| ICP Identifier | The identification string of the ICP server on which your system is running. |
| ICP IP Address | The IP address of the ICP server on which your system is running. |
| Extra BPF Rules | This field accepts a Berkeley Packet Filter (BPF) expression that the sensor applies directly to its traffic capture. BPF rules allow administrators to either include or exclude specific hosts, subnets, ports, or protocols from being processed by the sensor. This is useful in environments where certain traffic generates high throughput but provides no network security value. A common example is CCTV or IP camera streams, which can consume significant bandwidth on a monitored segment without contributing any meaningful data to OT asset visibility or threat detection. Filtering this traffic at the BPF layer reduces sensor load and focuses analysis on relevant network activity. |
| Sensor Monitoring Interfaces | These are the network interfaces the sensor uses for passive traffic monitoring. The sensor listens on each of these selected interfaces without transmitting any traffic of its own. Each monitoring interface must be connected to a SPAN, RSPAN, or port mirroring destination on a switch so that a switch delivers a copy of the network traffic to the sensor for analysis. Multiple interfaces can be selected by holding Cmd (macOS) or Ctrl (Windows) while making selections. |
| Active Sensor Interfaces | These are the network interfaces the sensor is permitted to use when issuing active queries to devices on the network. Active querying requires the sensor to transmit traffic, so these interfaces must have IP addresses and network reachability to the subnets being queried. When Sensor Active Queries are enabled and target subnets are defined, the sensor automatically determines which interface to use based on routing to the target device. Multiple interfaces can be selected by holding Cmd (macOS) or Ctrl (Windows) while making selections. |
The pairing information pulled from OT Security appears in the parameters described in the following table.
| Status Type | Current Status | User Interface Function |
|---|---|---|
| Pairing Status | Possible values are: Pairing and Waiting for ICP approval | Restart Pairing: You can click this button to use the previously saved credentials to start the pairing process again. Connects outside of the tunnel via HTTPS to reconfigure the tunnel to repair various broken connections. This is useful if your keys or certifications have changed. |
| Connection Status | Possible values are: Connected and Not Connected | Pause Data Transfer: You can enable or disable passing collected OT traffic data to the ICP with this button. |
The ICP certificate information for your OT Security Sensor instance.
| Parameter Name | Description |
|---|---|
| Certificate Subject | Human-readable certificate subject information. |
| Certificate Issuer | Human-readable certificate issuer information. |
| Certificate Fingerprint | Brief cryptographic hash that can be used to confirm the certification set on the ICP is the one being received by OT Security Sensor. |
| Not Valid Before | The beginning date for which the offered certificate is valid. |
| Not Valid After | The ending date for which the offered certificate is valid. |
| Approval Status |
Possible values are: Approved, N/A, Pending your approval, and Mismatching certificates |
| Upload Approved Certificate |
You can upload the ICP's certificate (.pem format) and pre-approve it as an alternative to examining the certificate fingerprint after the ICP offers it. This is helpful when configuring a sensor before it has network connectivity to the ICP, or before the ICP has been provisioned. The ICP needs the custom certificate and key applied before allowing the sensor to attempt a connection. |
The OT Security Sensor information page contains a tile for OT Security Sensor logs. For more information, see View Logs.