The following are prerequisites for the Infoblox SOC Insights integration:
Infoblox
Infoblox BloxOne with one of the following
BloxOne Threat Defense Business Cloud + BloxOne Threat Defense Ecosystem + SOC Insights
BloxOne Threat Defense Advanced + BloxOne Threat Defense Ecosystem + SOC Insights
An OPH (On-Prem Host) with the Data Connector service enabled. For deploying the Data Connector, refer to this guide.
A valid Infoblox API key with SOC Insight access. For generating API Key, refer Configuring User API Keys.
Tenable
Permission to create scans, access scan results, and manage assets.
Required role on Tenable: Scan Manager or Scan Operator
Generate the following
TenableAccessKey: The Tenable API access key.
TenableSecretKey: The Tenable API secret key.
TenableTemplateName: The Tenable scan template name (e.g., Basic Network Scan).
TenableScannerName: The Tenable scanner name (e.g., US Cloud Scanner).