Skip to main content
Question

Tenable.io integration into GoogleSecOps need help

  • June 4, 2026
  • 3 replies
  • 54 views

Vyasar
Forum|alt.badge.img

Dear All,

 

I need your help to understand  log ingestion for vulnerability management tool.   Currently in our environment , we are managing tenable.io vulnerability management console. We need to on-board the  vulnerability logs into GoogleSecops. On search , we found the below article  which is purely related to SOAR concept but we wish to understand how to on-board the logs from SIEM concept. Request  your kind support to address  this issue. As we are running out of time.                                                                    Tenable.io  |  Google Security Operations  |  Google Cloud Documentation

3 replies

a_aleinikov
Forum|alt.badge.img+7
  • Bronze 2
  • June 5, 2026

Hi Vyasar,

The link you shared includes the Tenable.io / Tenable Vulnerability Management integration for Google SecOps. The SOAR part is mainly for enrichment and actions, but for your SIEM-related use case you should also check the “Tenable IO - Vulnerabilities Connector” section in the same documentation.

That connector is intended to pull vulnerabilities from Tenable Vulnerability Management into Google SecOps, with options such as severity filter, status filter, time range, and grouping by host or vulnerability.

So if your goal is to onboard vulnerability findings from Tenable VM, this connector looks like the relevant starting point. If you need a different type of data, for example audit logs, assets, scan results, or CSPM findings, then the ingestion approach may be different and should be confirmed based on the exact data type.


Vyasar
Forum|alt.badge.img
  • Author
  • New Member
  • June 5, 2026

Hi  a_aleinikov,

 

Thank you for your reply. It helps me a lot but when I saw that section “Tenable IO - Vulnerabilities Connector”” on the same page. I saw a link “ how to configure a connector in Google SecOps, see Configuring the connector.” It again redirect to SOAR section to configure the connector.    Since I am  new to this platfomr, I  wish to understand this link will not comes under the SOAR concept ?  Please help me to understand.                                                                                                                                      

Thank you


cmorris
Staff
Forum|alt.badge.img+14
  • Staff
  • June 5, 2026

In SecOps, connectors are used to ingest alerts from a source to the SOAR - 

 

For Tenable, you can ingest the logs into the SIEM, write and configure rules for the events that you wish to alert on, and then receive those alerts in the SOAR via the Chronicle connector. You are also able to configure the Tenable connector that you linked to ingest those alerts directly to the SOAR.