General
General
What is the LevelBlue Vulnerability Scanner powered by Tenable?The LevelBlue Vulnerability Scanner powered by Tenable is the vulnerability scanning capability integrated with USM Anywhere. Customers enable the LevelBlue Vulnerability Scanner BlueApp, deploy one or more Tenable Nessus scanners where needed, launch supported scans from USM Anywhere, and view imported vulnerability results in USM Anywhere.
Is this replacing jOVAL?Yes. The legacy jOVAL scanner has been retired as of July 15, 2026. Customers should use the LevelBlue Vulnerability Scanner powered by Tenable for vulnerability scanning in USM Anywhere.
Can I still use jOVAL?No. jOVAL is no longer the supported scanner for USM Anywhere vulnerability scanning.
Is the LevelBlue Vulnerability Scanner replacing the Tenable.io BlueApp?No. The LevelBlue Vulnerability Scanner and the Tenable.io BlueApp are separate integrations.The LevelBlue Vulnerability Scanner is the integrated USM Anywhere vulnerability scanning workflow powered by Tenable. It supports USM Anywhere scan workflows such as asset scans, asset group scans, scheduled scans, and vulnerability result ingestion.The Tenable.io BlueApp is used when a customer has a separate Tenable Vulnerability Management subscription and wants to integrate that Tenable environment with USM Anywhere.
Can the LevelBlue Vulnerability Scanner coexist with the Tenable.io BlueApp?Yes, but using both may produce duplicate vulnerability data if the same assets are scanned or imported through both integrations.
Is the scanner included with my USM Anywhere subscription?Yes. The LevelBlue Vulnerability Scanner powered by Tenable is included with USM Anywhere at no additional scanner license cost.
Is this the same as Tenable Professional, Tenable Expert, Tenable.sc, or Tenable Vulnerability Management?No. The LevelBlue Vulnerability Scanner uses a custom Tenable license for the USM Anywhere integration. It should not be positioned as equivalent to Tenable Professional, Tenable Expert, Tenable.sc, or a full Tenable Vulnerability Management subscription.
Does TVS include Tenable VPR?No. Tenable Vulnerability Priority Rating, or VPR, is not included in TVS. Customers who need VPR or broader Tenable risk-prioritization capabilities should consider Tenable Vulnerability Management.
What data regions are supported?The following regions are supported: Australia, Brazil, Canada, European Union, India, Japan, Singapore, United Kingdom, and United States.
Deployment and installation
Deployment and installation
How is the Tenable scanner different from the previous jOVAL scanner?jOVAL was embedded in the USM Anywhere sensor. The Tenable scanner is deployed separately in the customer environment and linked to the Tenable cloud service used by the LevelBlue integration.
Can I install the Tenable scanner on the USM Anywhere sensor?No. The Tenable scanner cannot be installed on the same system as the USM Anywhere sensor.
What deployment method is recommended?A Tenable Core virtual appliance or supported marketplace image is recommended when available because it simplifies deployment and reduces operating system or dependency issues.
What are the minimum system requirements?The scanner should have at least 4 CPU cores and 8 GB of RAM.
Where can I install the scanner?The scanner can be deployed as a virtual appliance or installed on supported Windows, Linux, and macOS systems. It can also be deployed in cloud environments such as AWS, Azure, or Google Cloud when network reachability requirements are met.
Can I deploy more than one scanner?Yes. Customers can deploy multiple Tenable Nessus scanners for a USM Anywhere instance. This is common for MSSPs, segmented environments, and customers with multiple private networks.
Do I need one scanner per network?You need a scanner that can reach the assets being scanned. For private networks that are separated from each other, this usually means deploying a scanner inside each private network or in a network path that can reach the target assets.
Does the Tenable cloud scanner proxy scans into private networks?No. Tenable cloud scanners do not proxy or relay scans into private networks. A Nessus scanner must have direct network reachability to the private assets it scans.
Can I scan public IP addresses without deploying a local scanner?Yes, public IP addresses can be scanned using Tenable cloud scanners when the LevelBlue Vulnerability Scanner is configured.
Should I use cloud scanners or internal scanners?Use cloud scanners for public-facing assets. Use internal Nessus scanners for private assets, internal networks, and environments where authenticated scanning is required.
What ports does the scanner use?Tenable Nessus uses TCP 8834 for the Nessus interface and API access. The scanner also requires outbound TCP 443 access to Tenable cloud services and plugin update services.If using Tenable Core, TCP 8000 may be used for operating system-level management.
Does the scanner require inbound connections from Tenable?No. Scanner communication with Tenable cloud services is initiated outbound from the scanner.Administrative access to the scanner interface, such as TCP 8834 or Tenable Core management on TCP 8000, may still require inbound access from the customer’s approved management network.
How long does scanner initialization take?Initial setup can take up to 20 minutes while plugins download and the scanner completes registration. Do not start scans until plugin updates are complete.
Configuration and setup
Configuration and setup
How do I get started?Enable the LevelBlue Vulnerability Scanner powered by Tenable BlueApp in USM Anywhere. Select the appropriate data region, provide the required email address, and follow the in-product instructions to deploy and link a Tenable scanner.
How do I get the scanner linking key?The linking key is available from the LevelBlue Vulnerability Scanner BlueApp in USM Anywhere. Use that key to link the Tenable Nessus scanner to the Tenable cloud service used by the integration.
Is the linking key unique per scanner?No. The linking key is generated for the Tenable Vulnerability Management instance associated with the USM Anywhere instance. Multiple Nessus scanners can be linked with the same key.
Can I change my domain information after initial configuration?No. Domain information cannot be changed after initial setup.
Which USM Anywhere roles can configure the scanner?Only users with the USM Anywhere Manager role can configure the scanner and settings.
Do I need to configure scanner groups?Usually no. Scanner groups are only needed for advanced use cases where multiple scanners are used together for larger scan workloads or specific operational requirements.
Do I need to configure networks in Tenable?Usually no. Network configuration is mainly needed for overlapping IP address spaces or more advanced Tenable configurations.
Will existing asset credentials still work?Yes. USM Anywhere credential management remains available. Scan behavior depends on whether the selected Tenable scanner can use the credentials successfully against the target assets.
Are there Windows credential requirements I should know about?Yes. For Windows authenticated scans, Tenable uses SMB-based authentication. A successful credential test in USM Anywhere does not always guarantee that the Tenable scan will authenticate successfully during the scan.
Are Linux and macOS authenticated scans supported?Yes. SSH-based authentication is supported for Linux and macOS targets.
Scanning capabilities
Scanning capabilities
What scan workflows are supported from USM Anywhere?USM Anywhere supports vulnerability scan workflows such as individual asset scans, multi-asset scans, asset group scans, scheduled scans, and selected event-triggered scan actions.
What scan templates are available from USM Anywhere?The available scan templates are shown in the USM Anywhere interface. Common examples include Basic Network Scan, Advanced Network Scan, Credentialed Patch Audit, Cryptographic Inventory, and Internal PCI Network Scan.
Are all Tenable scan templates available from USM Anywhere?No. USM Anywhere supports a curated list of Tenable scan templates. Some Tenable templates require additional input or configuration that is not currently supported from the USM Anywhere workflow.
Can I run scans directly from the Tenable portal?Yes, but scans launched directly from the Tenable portal do not automatically appear in USM Anywhere. To ensure results are imported into USM Anywhere, launch scans from USM Anywhere.
Where can I view scan results?Scans launched from USM Anywhere are imported into USM Anywhere. Scans launched directly in the Tenable portal are visible in the Tenable portal.
What information do vulnerability results include?Results can include CVE IDs, severity, CVSS scores, vulnerability descriptions, affected assets, and remediation guidance. Some findings may not be tied to a CVE.
Does TVS support asset group scans?Yes. Asset group scans are supported from USM Anywhere.
Are scheduled scans preserved from jOVAL?No. Custom scheduled scan jobs from the legacy jOVAL scanner are not automatically migrated. Scheduled scan jobs should be recreated in USM Anywhere using the LevelBlue Vulnerability Scanner workflow.
Which scan actions are deprecated?Debug scan actions for assets and asset groups have been deprecated.
Are there license limits for private IP scanning?No. Private IP scanning is not limited by a per-IP scanner license in the LevelBlue TVS integration. Individual scan jobs may still be subject to platform or API limits.
Is there a limit per scan job?Individual scan jobs are limited to 8,192 assets per batch.
Can scan results include configuration issues?Tenable can identify configuration and compliance findings depending on the scan template and target configuration. Availability in USM Anywhere depends on the supported template and imported result data.
How do I check CVE coverage?Tenable CVE and plugin coverage can be reviewed on the public Tenable CVE page and Tenable Plugins page.
Customer portal access
Customer portal access
Can I access the Tenable portal directly?Yes. Customers receive access to the Tenable portal used by the LevelBlue Vulnerability Scanner integration. You can log in at cloud.tenable.com.
How do I log into the Tenable portal?After initial configuration, you receive an email with the portal link, username, and password.
Can I create additional Tenable portal users?Yes. Additional user accounts can be provisioned in the Tenable portal.
What can I do in the Tenable portal?You can review scanner status, manage scanner-related settings, manage Tenable users, review scans launched in Tenable, and perform certain Tenable-specific administrative tasks.
Should I use the Tenable portal for normal USM Anywhere scanning?For normal USM Anywhere vulnerability scanning, launch scans from USM Anywhere so results are imported into USM Anywhere.
Updates and maintenance
Updates and maintenance
How are scanner updates handled?Nessus scanner updates and plugin updates are delivered from Tenable. Operating system updates depend on the scanner deployment method and customer configuration.
Do scanner OS updates require a reboot?They may. Operating system updates are not always automatic and may require customer configuration and a reboot.
What happens if the scanner is offline?Scans that require that scanner will fail or remain unavailable until the scanner is back online and reachable.
Can I redeploy a scanner?Yes. A scanner can be redeployed and linked again. Scan history is stored in Tenable and USM Anywhere depending on where the scan was launched and where results were imported.
Troubleshooting and known limits
Troubleshooting and known limits
Why do some assets fail while others succeed in the same scan?The selected scanner must be able to reach each target asset. If some assets are reachable and others are not, reachable assets may scan successfully while unreachable assets fail.
Why did an authenticated Windows scan fail even though the credential test passed?Windows authenticated scans depend on SMB access and required Windows permissions. A USM Anywhere credential test does not always guarantee that the Tenable scanner can authenticate during the scan.
Why are scans not showing in USM Anywhere?Scans launched directly from the Tenable portal do not automatically import into USM Anywhere. Launch scans from USM Anywhere if you need results in USM Anywhere.
Why can’t I see VPR in TVS results?VPR is not included in TVS. Customers who need VPR should consider Tenable Vulnerability Management.
What happens if Tenable Cloud scan history reaches its scan limit?Tenable Cloud has limits on stored scan history. If scan history cleanup is needed, contact Support. Some cases may require old completed scans to be purged from the Tenable portal.
Can paused, running, or canceled scans be purged automatically from USM Anywhere?No. Purge behavior, where available, should only apply to completed scans that are eligible for deletion. Non-completed scans should not be deleted by cleanup actions.
Government and FedRAMP environments
Government and FedRAMP environments
Is the LevelBlue Vulnerability Scanner supported for TDRGov or Gov USM instances?The LevelBlue Vulnerability Scanner powered by Tenable can be enabled for Gov USM instances, but it is not a FedRAMP-authorized vulnerability management service.The current integration uses Tenable’s commercial cloud control plane for scanner management and orchestration. Vulnerability scan data is sent back into the Gov USM environment, but the Tenable control plane used by the included TVS integration is not FedRAMP-authorized.
Can customers with FedRAMP requirements use the included TVS integration?Customers with FedRAMP requirements should not treat the included TVS integration as a FedRAMP-authorized vulnerability management solution.If a customer chooses to use the included TVS integration in a Gov USM environment, that use should be at the customer’s discretion and based on their own compliance requirements.
Is there a FedRAMP-native TVS integration path for TDRGov?No. There is not a FedRAMP/TDRGov-native integrated TVS path for the included LevelBlue Vulnerability Scanner.
What should customers use if they require a formally FedRAMP-authorized vulnerability management service?Customers that require a formally FedRAMP-authorized vulnerability management service should work with their account team to evaluate Tenable’s FedRAMP-authorized TVM or Tenable One options.
Should we position TVS as something that will become formally FedRAMP certified?No. Since Tenable already has a formal FedRAMP product path, the included TVS integration should not be positioned as something that will become formally FedRAMP certified.
Is the Tenable portal still part of the Gov setup or admin workflow?Yes. The separate Tenable portal is still part of the current setup and administration workflow for scanner deployment and management, with scan results coming back into USM Anywhere.