Tenable IO Attribute Reference
Focus
Focus
Device Security

Tenable IO Attribute Reference

Table of Contents

Tenable IO Attribute Reference

This reference lists the attributes that Device Security collects from Tenable IO, their names as stored in Device Security, and the Device Security fields they map to.
When Device Security integrates with Tenable.io, it enhances vulnerability management for your devices. The attributes in this reference cover asset records from vulnerability exports, agent data, asset export details, scanner records, network interfaces, and individual vulnerability findings.
The third-party attribute name in Device Security refers to the attribute name as it appears in the Assets Inventory table and in Query Engine. This follows the format of third-party-name.attribute-name. When viewing the attribute name in the Assets Inventory table column selector or on a Device Details page, where the third-party name can be found as a header for the attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the Query Builder and in the Assets Inventory table, but under Device DetailsAttributesIntegration Specific AttributesMicrosoft Defender, the attribute would appear as macAddress.

Vulns Export Assets Attributes

Device Security collects vulns export assets attributes from Tenable IO. The following table lists each Tenable IO attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Tenable IO Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
asset.hostname
tenable_io.hostname
hostname
Name of the device
asset.mac_address
—
id; MAC
Mac address
asset.ipv4
tenable_io.ipv4
IP Address
Ipv4
asset.operating_system
tenable_io.operating_system
raw_os
Operating system
plugin.cpe
tenable_io.cpe
third_party_learned_installed_software
CPE
asset.agent_uuid
tenable_io.agent_uuid
—
Agent uuid
asset.device_type
tenable_io.device_type
—
Device type
asset.ipv6
tenable_io.ipv6
—
Ipv6
asset.last_authenticated_results
tenable_io.last_authenticated_results
—
Last authenticated results
asset.last_scan_target
tenable_io.last_scan_target
—
Last scan target
scan_details.creation_date
tenable_io.scan.creation_date
—
Creation date
scan_details.name
tenable_io.scan.name
—
Name of the device
scan_details.owner
tenable_io.scan.owner
—
Owner
scan_details.schedule_uuid
tenable_io.scan.schedule_uuid
—
Schedule uuid
scan.started_at
tenable_io.scan.started_at
—
Started at
scan_details.status
tenable_io.scan.status
—
Status of the device
scan_details.template_uuid
tenable_io.scan.template_uuid
—
Template uuid
scan_details.total_targets
tenable_io.scan.total_targets
—
Total targets
scan_details.type
tenable_io.scan.type
—
Type
asset.tracked
tenable_io.tracked
—
Tracked

Agents Attributes

Device Security collects agents attributes from Tenable IO. The following table lists each Tenable IO attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Tenable IO Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
ip
tenable_io.agent.ip
IP Address; id
IP
last_connect
—
Last Activity
Last connect
distro
tenable_io.agent.distro
raw_os
Distro
asset_uuid
tenable_io.agent.asset_uuid
—
Asset uuid
core_build
tenable_io.agent.core_build
—
Core build
core_version
tenable_io.agent.core_version
—
Core version
health
tenable_io.agent.health
—
Health status of the device
health_state_name
tenable_io.agent.health_state_name
—
Health state name
id
tenable_io.agent.id
—
Unique identifier
linked_on
tenable_io.agent.linked_on
—
Linked on
name
tenable_io.agent.name
—
Name of the device
nessus_scanning_health
tenable_io.agent.nessus_scanning_health
—
Nessus scanning health
network_name
tenable_io.agent.network_name
—
Network name
platform
tenable_io.agent.platform
—
Platform
profile_name
tenable_io.agent.profile_name
—
Profile name
runtime_scanning_health
tenable_io.agent.runtime_scanning_health
—
Runtime scanning health
status
tenable_io.agent.status
—
Status of the device
supports_remote_settings
tenable_io.agent.supports_remote_settings
—
Supports remote settings
uuid
tenable_io.agent.uuid
—
UUID
name
tenable_io.agent_name
—
Name of the device

Assets Export Attributes

Device Security collects assets export attributes from Tenable IO. The following table lists each Tenable IO attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Tenable IO Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
first_seen
tenable_io.first_seen
First Seen
First seen
last_seen
tenable_io.last_seen
Last Activity
Last seen
mac_addresses
tenable_io.mac_addresses
MAC
Mac addresses
operating_systems
tenable_io.operating_systems
raw_os
Operating systems
installed_software
tenable_io.installed_software
third_party_learned_installed_software
Installed software
network_interfaces
tenable_io.network_interfaces
third_party_learned_network_interfaces
Network interfaces
agent_names
tenable_io.agent_names
—
Agent names
id
tenable_io.asset_id
—
Unique identifier
first_scan_time
tenable_io.first_scan_time
—
First scan time
fqdns
tenable_io.fqdns
—
Fqdns
has_agent
tenable_io.has_agent
—
Has agent
hostnames
tenable_io.hostnames
—
Hostnames
ipv4s
tenable_io.ipv4s
—
Ipv4s
ipv6s
tenable_io.ipv6s
—
Ipv6s
last_authenticated_scan_date
tenable_io.last_authenticated_scan_date
—
Last authenticated scan date
last_authentication_scan_status
tenable_io.last_authentication_scan_status
—
Last authentication scan status
last_licensed_scan_date
tenable_io.last_licensed_scan_date
—
Last licensed scan date
last_scan_id
tenable_io.last_scan_id
—
Last scan ID
last_scan_target
tenable_io.last_scan_target
—
Last scan target
last_scan_time
tenable_io.last_scan_time
—
Last scan time
last_schedule_id
tenable_io.last_schedule_id
—
Last schedule ID
netbios_names
tenable_io.netbios_names
—
Netbios names
network_id
tenable_io.network_id
—
Network ID
network_name
tenable_io.network_name
—
Network name
open_ports
tenable_io.open_ports
—
Open ports
sources
tenable_io.sources
—
Sources
tags
tenable_io.tags
—
Tags

Scanners Attributes

Device Security collects scanners attributes from Tenable IO. The following table lists each Tenable IO attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Tenable IO Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
hostname
tenable_io.scanner.hostname
hostname
Name of the device
last_connect
tenable_io.scanner.last_connect
Last Activity
Last connect
distro
tenable_io.scanner.distro
raw_os
Distro
creation_date
tenable_io.scanner.creation_date
—
Creation date
engine_version
tenable_io.scanner.engine_version
—
Engine version
group
tenable_io.scanner.group
—
Group
id
tenable_io.scanner.id
—
Unique identifier
ip_addresses
tenable_io.scanner.ip_addresses
—
Ip addresses
last_modification_date
tenable_io.scanner.last_modification_date
—
Last modification date
linked
tenable_io.scanner.linked
—
Linked
loaded_plugin_set
tenable_io.scanner.loaded_plugin_set
—
Loaded plugin set
name
tenable_io.scanner.name
—
Name of the device
network_name
tenable_io.scanner.network_name
—
Network name
num_scans
tenable_io.scanner.num_scans
—
Num scans
owner_name
tenable_io.scanner.owner_name
—
Owner name
platform
tenable_io.scanner.platform
—
Platform
scan_count
tenable_io.scanner.scan_count
—
Number of scans
source
tenable_io.scanner.source
—
Source
status
tenable_io.scanner.status
—
Status of the device
supports_remote_logs
tenable_io.scanner.supports_remote_logs
—
Supports remote logs
supports_remote_settings
tenable_io.scanner.supports_remote_settings
—
Supports remote settings
supports_webapp
tenable_io.scanner.supports_webapp
—
Supports webapp
type
tenable_io.scanner.type
—
Type
user_permissions
tenable_io.scanner.user_permissions
—
User permissions
uuid
tenable_io.scanner.uuid
—
UUID

Assets Export Interfaces Attributes

Device Security collects assets export interfaces attributes from Tenable IO. The following table lists each Tenable IO attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Tenable IO Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
ipv4s
tenable_io.ipv4s
IP Address
Ipv4s
mac_addresses
tenable_io.mac_addresses
MAC; id
Mac addresses
network_interfaces
tenable_io.network_interfaces
third_party_learned_network_interfaces
Network interfaces

Vulns Export Vulns Attributes

Device Security collects vulns export vulns attributes from Tenable IO. The following table lists each Tenable IO attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Tenable IO Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
cves
—
cve
Cves
plugin.cvss_base_score
tenable_io.cvss_base_score
cvss_base_score
Cvss base score
plugin.cvss3_base_score
tenable_io.cvss3_base_score
cvss_v3base_score
Cvss3 base score
plugin.description
tenable_io.plugin.description
Description
Description
first_found
tenable_io.first_found
detected_time; First Seen
First found
asset.mac_address
—
id
Mac address
asset.ipv4
tenable_io.ipv4
IP Address
Ipv4
last_found
tenable_io.last_found
last_seen
Last found
plugin.exploit_available
—
public_exploit
Exploit available
asset.operating_system
—
raw_os
Operating system
severity
tenable_io.severity
risk_level; severity
Severity
plugin.solution
tenable_io.plugin.solution
solution
Solution
plugin.name
tenable_io.plugin.name
title
Name of the device
plugin.id
—
vulnerability_id
Unique identifier
plugin.has_patch
tenable_io.plugin.has_patch
—
Has patch
plugin.has_workaround
tenable_io.plugin.has_workaround
—
Has workaround
plugin.modification_date
tenable_io.plugin.modification_date
—
Modification date
plugin.publication_date
tenable_io.plugin.publication_date
—
Publication date
plugin.version
tenable_io.plugin.version
—
Version
port
tenable_io.port
—
Port
port.protocol
tenable_io.protocol
—
Protocol
scan_details.creation_date
tenable_io.scan.creation_date
—
Creation date
scan_details.name
tenable_io.scan.name
—
Name of the device
scan_details.owner
tenable_io.scan.owner
—
Owner
scan_details.schedule_uuid
tenable_io.scan.schedule_uuid
—
Schedule uuid
scan.started_at
tenable_io.scan.started_at
—
Started at
scan_details.status
tenable_io.scan.status
—
Status of the device
scan_details.template_uuid
tenable_io.scan.template_uuid
—
Template uuid
scan_details.total_targets
tenable_io.scan.total_targets
—
Total targets
scan_details.type
tenable_io.scan.type
—
Type
* Only some attributes map to a Device Security Common Attribute.