Can someone please help me on how i can integrate (ingestion method) Tenable IVM and Tenable Access control Chronicle SIEM
Hello,
You could use the ingestion API which is located here.
https://cloud.google.com/chronicle/docs/reference/ingestion-api
Below are the supported products by Chronicle SIEM, for the two products you mentioned, what's the link to the product page? So I can check and give more details.
Please find the link below:
Main page
https://cloud.tenable.com/tio/app.html#/myapps
Once click on vulnerability management
https://cloud.tenable.com/tio/app.html#/vulnerability-management/dashboard/uw?appConfig=eyJzZWxlY3Rl...
Thanks for getting back to us. We are routed to a page that requires authentication and ultimately as my colleagues mentioned, we support a series of tenable products, including Cloud Security Posture Management and usually they are ingested through forwarders and the expected formats are here: https://cloud.google.com/chronicle/docs/ingestion/parser-list/supported-default-parsers
We advise to already look into ingesting those logs and take it from there. Chances are that existing ingestion methods and parsers will already do the job. If customization is required, we can do that too.