Add a Log Correlation Engine Server
Required User Role: Administrator
Tip: You can configure more than one Log Correlation Engine to work with Tenable.sc.
Before you begin:
- Confirm you understand the complete scanning configuration process, as described in Log Correlation Engines.
To add an LCE server to Tenable.sc:
-
Log in to Tenable.sc via the user interface.
-
Click Resources > Log Correlation Engines.
The LCE Servers page appears.
-
At the top of the table, click Add.
The Add LCE Server window appears.
-
Configure the General options, as described in Log Correlation Engines.
- In the Name box, type a name for the LCE server.
- In the Description box, type a description for the LCE server.
- In the Host box, type the hostname or IP address for the LCE server.
- In the Port box, view the default (1243) and modify, if necessary.
-
(Optional) To allow Tenable.sc to log in to the LCE server and retrieve vulnerability information:
-
Enable Import Vulnerabilities.
Note: If you use an LCE server with Tenable.sc, Tenable.sc counts the IP addresses associated with each imported instance against your license. For more information, see License Requirements.
- Select a Repository for the event vulnerability data.
- Type a Username and Password you want Tenable.sc to use for access to the LCE server.
-
-
Click Submit.
Tenable.sc saves your configuration.
-
(Optional) If you enabled the Check Authentication option above, Tenable.sc checks its ability to authenticate with the LCE server.
-
If authentication is successful, Tenable.sc displays a message to acknowledge that fact.
-
If authentication fails, Tenable.sc prompts you for credentials to the LCE server:
-
Type a username and password.
-
Click Push Key to initiate the transfer of the SSH Key.
If the transfer is successful, Tenable.sc displays a message to acknowledge that fact.
-
-