System and License Requirements

To install and run Tenable Core + Tenable Security Center, your application and system must meet the following requirements established for Tenable Security Center. For more information about Tenable Security Center requirements, see Tenable Security Center in the General Requirements User Guide.

Note: Tenable Support does not assist with issues related to your host operating system, even if you encounter them during installation or deployment.

Environment Tenable Core File Format More Information
Virtual Machine VMware .ova file

Deploy Tenable Core in VMware

Microsoft Hyper-V .zip file

Deploy Tenable Core in Hyper-V

KVM .qcow2 file

Deploy Tenable Core in KVM

Cloud Microsoft Azure n/a

Deploy Tenable Core in Microsoft Azure

Cloud Amazon Web Services (AWS) n/a

Deploy Tenable Core in AWS

Hardware

.iso image

Install Tenable Core on Hardware

Note: While you could use the packages to run Tenable Core in other environments, Tenable does not provide documentation for those procedures.

License Requirements

To deploy Tenable Core + Tenable Security Center, your Tenable Security Center application must meet the requirements described in Tenable Security Center Licensing Requirements in the General Requirements User Guide.

Tenable Security Center Hardware Requirements

Note: Tenable does not recommend deploying multiple applications on a single instance of Tenable Core. If you want to deploy several applications on Tenable Core, deploy a unique instance for each application.

You can run Tenable Security Center on hardware, with or without Tenable Core. For more information about Tenable Core, see the Tenable Core User Guide.

Note: Tenable strongly discourages running Tenable Security Center or Tenable CoreTenable Security Center in an environment shared with other Tenable applications.

Note: Complex deployments require more resources. For example, deployments with large numbers of organizations or application objects. For more information, see Performance in the Tenable Security Center Large Deployment Guide.

Storage Requirements

Tenable recommends installing Tenable Security Center on direct-attached storage (DAS) devices (or storage area networks [SANs], if necessary) with a storage latency of 10 milliseconds or less.

Tenable does not support installing Tenable Security Center on network-attached storage (NAS), including network filesystems such as NFS.

Disk Space Requirements (6.9.x and earlier)

Enterprise networks can vary in performance, capacity, protocols, and overall activity. Resource requirements to consider for deployments include raw network speed, the size of the network being monitored, and the configuration of the application. Processors, memory, and network cards are heavily based on the former. Disk space requirements vary depending on usage based on the amount and length of time data is stored on the system.

An important consideration is that Tenable Security Center can be configured to save a snapshot of vulnerability archives each day. In addition, the size of the vulnerability data stored by Tenable Security Center depends on the number and types of vulnerabilities, not just the number of hosts. For example, 100 hosts with 100 vulnerabilities each could consume as much data as 1,000 hosts with 10 vulnerabilities each. In addition, the output for vulnerability check plugins that do directory listings, etc. is larger than Open Port plugins from discovery scans.

For networks of 35,000 to 50,000 hosts, Tenable has encountered data sizes of up to 25 GB. That number is based on storage of 50,000 hosts and approximately 500 KB per host.

Additionally, during active scanning sessions, large scans, and multiple smaller scans have been reported to consume as much as 150 GB of disk space as results are acquired. Once a scan has completed and its results are imported, that disk space is freed up.

Note: To estimate disk space for vulnerability trending, use the following formula:

(repository size) × (days trending) × (growth factor) = estimated disk space required per repository

To find your current repository size, generate a Diagnostics report and open sc-dirlistings.txt. Look for entries under /opt/sc/repositories/<id>/. The total value listed is in kilobytes. Use the largest repository size as your baseline. Tenable recommends applying a growth factor of two to three times the current repository size to account for future data growth. Multiply the result by the number of repositories to get the total disk space needed in /opt/sc.

For example, if your largest repository is 2.7 GB and you want 21 days of trending with a growth factor of 3: 2.7 GB × 21 × 3 = approximately 170 GB per repository.

Note: In the sizing tables, Hosts refers to the total number of IP addresses and devices stored across all repositories in Tenable Security Center. This number does not refer to the number of licensed assets. To determine your host count, log in as an administrator, go to the Repositories section, and review the total number of IP addresses and devices across all repositories.

Note: Tenable Security Center recommends a minimum of 16 GB RAM for all installations. Tenable Security Center will not operate with less than 8 GB RAM.

Requirements When Running Basic Network Scans + Local Checks

Version

# of Hosts Managed by Tenable Security Center

CPU Cores

Memory

Disk Space used for Vulnerability Trending

6.7.x and later

2,500 active IPs

8 2GHz cores

16 GB RAM

90 days: 130 GB

180 days: 260 GB

10,000 active IPs

16 3GHz cores

32 GB RAM

90 days: 450 GB

180 days: 900 GB

25,000 active IPs

32 3GHz cores

64 GB RAM

90 days: 2.4 TB

180 days: 5 TB

100,000 active IPs

48 3GHz cores

96 GB RAM

90 days: 4.5 TB

180 days: 9 TB

6.6.x and earlier

2,500 active IPs

4 2GHz cores

8 GB RAM

90 days: 125 GB

180 days: 250 GB

10,000 active IPs

8 3GHz cores

16 GB RAM

90 days: 450 GB

180 days: 900 GB

25,000 active IPs

16 3GHz cores

32 GB RAM

90 days: 2.4 TB

180 days: 5 TB

100,000 active IPs

32 3GHz cores

64 GB RAM

90 days: 4.5 TB

180 days: 9 TB

Requirements When Running Basic Network Scans + Local Checks + 1 Configuration Audit

Version

# of Hosts Managed by Tenable Security Center

CPU Cores

Memory

Disk Space used for Vulnerability Trending

6.7.x and later

2,500 active IPs

8 2GHz cores

16 GB RAM

90 days: 225 GB

180 days: 400 GB

10,000 active IPs

16 3GHz cores

32 GB RAM

90 days: 900 GB

180 days: 1.8 TB

25,000 active IPs

32 3GHz cores

64 GB RAM

90 days: 4.5 TB

180 days: 9 TB

100,000 active IPs

48 3GHz cores

128 GB RAM

90 days: 9 TB

180 days: 18 TB

6.6.x and earlier

2,500 active IPs

4 2GHz cores

8 GB RAM

90 days: 225 GB

180 days: 450 GB

10,000 active IPs

8 3GHz cores

16 GB RAM

90 days: 900 GB

180 days: 1.8 TB

25,000 active IPs

16 3GHz cores

32 GB RAM

90 days: 4.5 TB

180 days: 9 TB

100,000 active IPs

32 3GHz cores

128 GB RAM

90 days: 9 TB

180 days: 18 TB

Note: Tenable Security Center is a memory and disk I/O-intensive application. If you deploy Tenable Security Center in a virtualized infrastructure, take care to avoid running Tenable Security Center in a manner in which it may attempt to draw on oversubscribed resources, especially memory and disk I/O. Refer to your vendor-specific virtualized infrastructure documentation for guidance on optimizing virtual infrastructure resource allocation.

Note: Upsize your Tenable Security Center hardware resources (CPU/memory) proportionally based on the Tenable Security Center recommendations. For example, upsize the instance from 8 CPU/16 GB RAM to 16 CPU/32 GB RAM, and not to 16 CPU/20 GB RAM.

Disk Space Requirements (6.10.x and later)

Disk requirements for Tenable Security Center 6.9 and later are primarily driven by scan result storage.

Estimation only: Many factors influence actual disk usage, including scan plugin selection, the number and types of findings per host, scan concurrency, the number of repositories, organization count, and configured retention periods. The values in this section are high-water-mark estimates intended for capacity planning purposes. Actual usage will vary. Monitor disk utilization after deployment and adjust retention settings as needed.

Tenable recommends installing Tenable Security Center on direct-attached storage (DAS) or a SAN with latency of 10 milliseconds or less. NAS and NFS are not supported. High-performance disks (SSDs) are strongly recommended. The /opt partition should reside on a dedicated disk or partition separate from the operating system.

Note: Tenable Security Center recommends a minimum of 16 GB RAM for all installations. Tenable Security Center will not operate with less than 8 GB RAM.

Disk Space Components

Component Size Notes
Scan result storage Scales with host count, scan frequency, and retention Dominant driver. See sizing tables below.
Repository data

~1 MB per host (with local checks)

~2 MB per host (with local checks and 1 compliance audit)

 
OS, plugins, and application databases ~23 GB Flat overhead included in sizing tables below.
Active scan temp space 150 GB baseline (peak; scales with deployment) Ephemeral. Required under /opt during active scans.
Upgrade temp space

~6 GB

~10 GB

Required in /tmp during upgrades.

Scan Result Sizing

The following tables apply to directly attached Nessus scanners without scan attachments enabled. If you are using linked scanners or have plugin attachments enabled, see Linked Scanners or Enabling Plugin Attachments below for additional sizing guidance.

The following tables show total disk requirements based on weekly scans with a 60-day retention period (9 scans stored). Scan result sizes assume a high-water mark of 250 findings per host per scan.

Basic Network Scans + Local Checks (Credentialed)

Active IPs Repository Data Scan Results (9 scans) Flat Overhead Total Disk Required
2,500 2.5 GB 13.5 GB 23 GB 39 GB
10,000 10 GB 54 GB 23 GB 87 GB
25,000 25 GB 135 GB 23 GB 183 GB
100,000 100 GB 540 GB 23 GB 663 GB

Basic Network Scans + Local Checks + 1 Configuration Audit

Active IPs Repository Data Scan Results (9 scans) Flat Overhead Total Disk Required
2,500 5 GB 36 GB 23 GB 64 GB
10,000 20 GB 144 GB 23 GB 187 GB
25,000 50 GB 360 GB 23 GB 433 GB
100,000 200 GB 1.44 TB 23 GB 1.66 TB

Note: Add up to 150 GB of additional headroom for active scan temp space. This space is reclaimed after scans complete but must be available on the /opt partition during scanning.

Adjusting for Scan Frequency and Retention

The tables above assume weekly scans with a 60-day retention period. To calculate disk requirements for different configurations, use the following approach:

  • Scan results per year: (scans per week) × 52 × (30 MB per 50 hosts scanned)

  • Retention adjustment: Multiply by (retention days ÷ 365) to scale proportionally.

  • Compliance audit adjustment: For environments running basic network scans plus one configuration audit, use (active IPs ÷ 50) × 80 MB per scan instead of the 30 MB figure above (1.6 MB per host per scan).

The default scan result retention period is 365 days and is configurable. Reducing retention is the most effective way to reduce disk consumption.

Note: The tables in this section use 60-day retention as the sizing example (9 weekly scans stored). At the default retention of 365 days, multiply the scan result storage figures by approximately 6× (52 scans stored instead of 9). Reducing retention from the default is the most effective way to control disk consumption.

Linked Scanners or Enabling Plugin Attachments

When using linked scanners or when plugin attachments are enabled, scan results take up significantly more disk space than the directly attached baseline. Use the following per-host estimates when sizing scan result storage:

  • Credentialed vulnerability scans: 4 MB per host per scan

  • Configuration audits: 2 MB per host per scan

For example, a weekly scan of 2,500 hosts with 60-day retention (9 scans) requires approximately 90 GB of scan result storage for credentialed vulnerability scans. Multiply by your host count, scan frequency, and configured retention period to determine total allocation.

For a combined credentialed vulnerability scan and one configuration audit, use 6 MB per host per scan (4 MB + 2 MB); a weekly scan of 2,500 hosts with 60-day retention (9 scans) requires approximately 135 GB of scan result storage. Multiply by your host count, scan frequency, and configured retention period to determine total allocation.

Amazon EC2 Instance Type Sizing Tables

Requirements When Running Basic Network Scans + Local Checks

# of Hosts Managed by Tenable Security Center

EC2 Instance Type

Total Disk Required

1 to 2,500

m5.2xlarge

39 GB

2,501 to 10,000

m5.4xlarge

87 GB

10,001 to 25,000

m5.8xlarge

183 GB

25,001 to 50,000

m5.12xlarge

343 GB

50,001 or more

For assistance with large enterprise deployments greater than 50,000 active IP addresses, contact your Tenable representative.

Requirements When Running Basic Network Scans + Local Checks + 1 Configuration Audit

# of Hosts Managed by Tenable Security Center

EC2 Instance Type

Total Disk Required

1 to 2,500

m5.2xlarge

64 GB

2,501 to 10,000

m5.4xlarge

187 GB

10,001 to 25,000

m5.8xlarge

433 GB

25,001 to 50,000

m5.12xlarge

843 GB

50,001 or more

For assistance with large enterprise deployments greater than 50,000 active IP addresses, contact your Tenable representative.

Supported Azure Instance Types

You can install Tenable Security Center in an Azure Virtual Machine (Azure Virtual Image) cloud-based environment that meets all of the following requirements. Tenable recommends the following virtual machine instance types based on your Tenable Security Center deployment size. You may need to increase the storage allocated to the virtual machine instance depending on usage.

Requirements When Running Basic Network Scans + Local Checks

# of Hosts Managed by Tenable Security Center

Virtual Machine Instance

Total Disk Required

1 to 2,500

D4s_v3

39 GB

2,501 to 10,000

D16s_v3

87 GB

10,001 to 25,000

D32s_v3

183 GB

25,001 to 50,000

D48s_v3

343 GB

50,001 or more

For assistance with large enterprise deployments greater than 50,000 active IP addresses, contact your Tenable representative.

Requirements When Running Basic Network Scans + Local Checks + 1 Configuration Audit

# of Hosts Managed by Tenable Security Center

Virtual Machine Instance

Total Disk Required

1 to 2,500

D4s_v3

64 GB

2,501 to 10,000

D16s_v3

187 GB

10,001 to 25,000

D32s_v3

433 GB

25,001 to 50,000

D48s_v3

843 GB

50,001 or more

For assistance with large enterprise deployments greater than 50,000 active IP addresses, contact your Tenable representative.

Supported Google Cloud Platform (GCP) Instance Types

You can install Tenable Security Center in a GCP cloud-based environment that meets all of the following requirements. Tenable Security Center uses a balance of networking and compute resources and requires persistent storage for proper operation. Tenable recommends the following GCP instance types based on your Tenable Security Center deployment size.

Requirements When Running Basic Network Scans + Local Checks

# of Hosts Managed by Tenable Security Center

GCP Instance Type

Total Disk Required

1 to 2,500

c4a-standard-8

39 GB

2,501 to 10,000

c4a-standard-16

87 GB

10,001 to 25,000

c4a-standard-32

183 GB

25,001 to 50,000

c4a-standard-48

343 GB

50,001 or more

For assistance with large enterprise deployments greater than 50,000 active IP addresses, contact your Tenable representative.

Requirements When Running Basic Network Scans + Local Checks + 1 Configuration Audit

# of Hosts Managed by Tenable Security Center

GCP Instance Type

Total Disk Required

1 to 2,500

c4a-standard-8

64 GB

2,501 to 10,000

c4a-standard-16

187 GB

10,001 to 25,000

c4a-standard-32

433 GB

25,001 to 50,000

c4a-standard-48

843 GB

50,001 or more

For assistance with large enterprise deployments greater than 50,000 active IP addresses, contact your Tenable representative.

External PostgreSQL

Deployments exceeding 100,000 active IPs require an external PostgreSQL instance. Repository data, trending results, and configuration data are stored in PostgreSQL. Size the external PostgreSQL instance using the repository data figures from the tables above as a baseline, and account for growth as scan and configuration data accumulates over time.

Disk Partition Requirements

Note: When you upgrade to or install Tenable Security Center version 6.2.x and run the RPM from the /tmp folder, you must have at least 3 GB of space in the /tmp folder if the /tmp folder is in its own partition.

Note: When you upgrade to or install Tenable Security Center version 6.3.x and run the RPM from the /tmp folder, you must have at least 4 GB of space in the /tmp folder if the /tmp folder is in its own partition.

Note: When you upgrade to or install Tenable Security Center version 6.4.x and run the RPM from the /tmp folder, you must have at least 4 GB of space in the /tmp folder if the /tmp folder is in its own partition.

Note: When you upgrade to or install Tenable Security Center version 6.5.x and run the RPM from the /tmp folder, you must have at least 5 GB of space in the /tmp folder if the /tmp folder is in its own partition.

Note: When you upgrade to or install Tenable Security Center version 6.6.x and run the RPM from the /tmp folder, you must have at least 6 GB of space in the /tmp folder if the /tmp folder is in its own partition.

Note: When you upgrade to or install Tenable Security Center version 6.7.x and run the RPM from the /tmp folder, you must have at least 6 GB of space in the /tmp folder if the /tmp folder is in its own partition.

Note: When you upgrade to or install Tenable Security Center version 6.8.x and run the RPM from the /tmp folder, you must have at least 6 GB of space in the /tmp folder if the /tmp folder is in its own partition.

Note: When you upgrade to or install Tenable Security Center version 6.9.x and run the RPM from the /tmp folder, you must have at least 10 GB of space in the /tmp folder if the /tmp folder is in its own partition.

Note: When you upgrade to or install Tenable Security Center and run the RPM from the /tmp folder, the /tmp folder must have enough space if it is in its own partition:

  • Tenable Security Center 6.2.x - at least 3 GB of space

  • Tenable Security Center 6.3.x and 6.4.x - at least 4 GB of space

  • Tenable Security Center 6.5.x - at least 5 GB of space

  • Tenable Security Center 6.6.x through 6.8.x - at least 6 GB of space

  • Tenable Security Center 6.9.x and later - at least 10 GB of space

Tenable Security Center installs into /opt/sc. Tenable highly recommends that you create the /opt directory on a separate disk partition. If you want to increase performance, consider using two disks: one for the operating system and one for the system deployed to /opt.

Tenable strongly recommends using high-performance disks. Tenable Security Center is a disk-intensive application and using disks with high read/write speeds, such as SSDs, results in the best performance.

If required disk space exists outside of the /opt file system, mount the desired target directory using the command mount –-bind <olddir> <newdir>. Make sure that the file system is automatically mounted on reboot by editing the /etc/fstab file appropriately.

Note: Tenable Security Center does not support using symbolic links for /opt/sc/. You can use symbolic links within /opt/sc/ subdirectories if instructed by Tenable Security Center documentation or Tenable Support.

Deploying Tenable Security Center on a server configured with RAID disks can also dramatically boost performance.

Tip:Tenable does not require RAID disks for even our largest customers. However, in one instance, response times for queries with a faster RAID disk for a customer with more than 1 million managed vulnerabilities moved from a few seconds to less than a second.

Network Interface Requirements

You can install Tenable Security Center in externally connected or air-gapped environments. For more information about special considerations for air-gapped environments, see Considerations for Air-Gapped Environments.

Gigabit or faster network cards are recommended for use on the Tenable Security Center server. This is to increase the overall performance of web sessions, emails, Tenable Log Correlation Engine queries, and other network activities.

External PostgreSQL Requirements

You can install Tenable Security Center configured to work with a PostgreSQL instance managed by you. PostgreSQL is required for certain features introduced in Tenable Security Center 6.5.0. For more information about connecting a PostgreSQL database, see Connect an External PostgreSQL Server.

This is a required configuration if you have more than 100K hosts.Tenable Security Center supports PostgreSQLversion 16 or laterversions 13 through 17.Tenable Security Center 6.5.x supports PostgreSQL version 16 or later. Tenable Security Center 6.6.x and later supports PostgreSQL versions 13 through 17. It is also recommended that wal_segment_size is set to be at least 64MB.

Your PostgreSQL instance should meet the following sizing requirements. Please note that the disk space in the following table is only for PostgreSQL data, and does not include any other OS or other dependencies you have.

# of Hosts Managed by Tenable Security Center CPU Cores Memory Minimum Disk Space Required for PostgreSQL Data
2,500 active IPs 4 16 GB RAM 20 GB
10,000 active IPs 8 32 GB RAM 50 GB
25,000 active IPs 16 64 GB RAM 100 GB
100,000 active IPs 32 128 GB RAM 400 GB
250,000 active IPs 64 256 GB RAM 1 TB