↳ GitHub sourceConnector

Tenable Identity Exposure

Description

Tenable Identity Exposure connector allows Indicators of Exposure, Indicators of Attack and trailflow logs to be ingested into Microsoft Sentinel.The different work books and data parsers allow you to more easily manipulate logs and monitor your Active Directory environment. The analytic templates allow you to automate responses regarding different events, exposures and attacks.
Declared status
1
Declared author / publisher
Tenable

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

read and write permissions are required.
Workspace
Workspace
read permissions to shared keys for the workspace are required. [See the documentation to learn more about workspace keys](https://docs.microsoft.com/azure/azure-monitor/platform/agent-windows#obtain-workspace-id-and-key).
Keys
Workspace
Access to TenableIE Configuration
Permissions to configure syslog alerting engine

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

>This data connector depends on [afad_parser](https://aka.ms/sentinel-TenableApp-afad-parser) based on a Kusto Function to work as expected which is deployed with the Microsoft Sentinel Solution.
1. Configure the Syslog server
You will first need a **linux Syslog** server that TenableIE will send logs to. Typically you can run **rsyslog** on **Ubuntu**. You can then configure this server as you wish, but it is recommended to be able to output TenableIE logs in a separate file. Configure rsyslog to accept logs from your TenableIE IP address. Choose one of the following options: **Option 1: Using AllowedSender directive** This configuration restricts which hosts can send logs to your syslog server at the network level. It's more secure as it rejects unauthorized connections before processing them. 1. Download the configuration file: [80-tenable-allowedsender.conf](https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Tenable%20App/Data%20Connectors/TenableIE/80-tenable-allowedsender.conf) 2. Run in sudo mode: `sudo -i` 3. Set your TenableIE IP address: `export TENABLE_IE_IP={Enter your IP address}` 4. Execute the commands from the downloaded configuration file 5. Restart rsyslog: `systemctl restart rsyslog` **Option 2: Filter logs by source IP (For environments with multiple syslog sources)** This configuration accepts all incoming logs but only processes those from the specified TenableIE IP address. It's particularly useful when you have multiple syslog servers or applications sending logs to the same syslog server, and you want to selectively process only TenableIE logs. 1. Download the configuration file: [80-tenable-filter.conf](https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Tenable%20App/Data%20Connectors/TenableIE/80-tenable-filter.conf) 2. Run in sudo mode: `sudo -i` 3. Set your TenableIE IP address: `export TENABLE_IE_IP={Enter your IP address}` 4. Execute the commands from the downloaded configuration file 5. Restart rsyslog: `systemctl restart rsyslog`
2. Install and onboard the Microsoft agent for Linux
The OMS agent will receive the TenableIE syslog events and publish it in Microsoft Sentinel :
Choose where to install the agent:
Install agent on Azure Linux Virtual Machine
Select the machine to install the agent on and then click **Connect**.
Install agent on a non-Azure Linux Machine
Download the agent on the relevant machine and follow the instructions.
3. Check agent logs on the Syslog server
```shell tail -f /var/opt/microsoft/omsagent/log/omsagent.log ```
4. Configure TenableIE to send logs to your Syslog server
On your **TenableIE** portal, go to *System*, *Configuration* and then *Syslog*. From there you can create a new Syslog alert toward your Syslog server. Once this is done, check that the logs are correctly gathered on your server in a separate file (to do this, you can use the *Test the configuration* button in the Syslog alert configuration in TenableIE). If you used the Quickstart template, the Syslog server will by default listen on port 514 in UDP and 1514 in TCP, without TLS. Note: Both configuration options from Step 1 configure the syslog server to listen on port 514 for both UDP and TCP connections.
5. Configure the custom logs
Configure the agent to collect the logs. 1. In Microsoft Sentinel, go to **Configuration** -> **Settings** -> **Workspace settings** -> **Custom logs**. 2. Click **Add custom log**. 3. Upload a sample TenableIE.log Syslog file from the **Linux** machine running the **Syslog** server and click **Next** 4. Set the record delimiter to **New Line** if not already the case and click **Next**. 5. Select **Linux** and enter the file path to the **Syslog** file, click **+** then **Next**. The default location of the file is `/var/log/TenableIE.log` if you have a Tenable version <3.1.0, you must also add this linux file location `/var/log/AlsidForAD.log`. 6. Set the **Name** to *Tenable_IE_CL* (Azure automatically adds *_CL* at the end of the name, there must be only one, make sure the name is not *Tenable_IE_CL_CL*). 7. Click **Next**, you will see a resume, then click **Create**
6. Enjoy !
> You should now be able to receive logs in the *Tenable_IE_CL* table, logs data can be parse using the **afad_parser()** function, used by all query samples, workbooks and analytic templates.

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
TenableIE
Additional source files 2Solutions/Tenable App/Data Connectors/TenableIE/TenableIE.jsonsource ↗Solutions/Tenable App/Data/Solution_TenableApp.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.