Device Intelligence prend en charge l’intégration avec les plugins suivants :
- Tanium
- Qualys
- ServiceNow
- Infoblox
- Microsoft Entra ID (anciennement Azure AD)
- Forescout
- SentinelOne
- Tenable
- Kaseya VSA
- SuperOps
- Crowdstrike
Cet article fournit des informations détaillées pour chaque plugin.
Intégration Tanium
Le plugin Tanium récupère les données périphérique inventoriées du module Assets.
Required Configuration Parameters
- Tanium Host: Instance URL of the Tanium platform
- API Token: Jeton d'API pour l'instance Tanium
Device Attributes
Device Intelligence cartographie les champs suivants à partir de Titanium :
| Champ source de tanium | Type de données |
|---|---|
| ci_network_adapter.mac_address | String |
| system_uuid | String |
| user_name[ :32] | String |
| computer_name | String |
| ip_address | String |
| city, country | String |
| last_seen_at | String |
| manufacturer | String |
| model | String |
| operating_system | String |
| os_version | String |
| serial_number | String |
Intégration Qualys
Le plugin Qualys récupère les données d'inventaire des actifs et de vulnérabilité depuis la plateforme Qualys.
Required Configuration Parameters
- UsernameNom d'utilisateur pour l'instance Qualys
- Password: Mot de passe pour l’instance Qualys
- Qualys API Gateway URLURL de la passerelle API de la plateforme Qualys
Device Attributes
Device Intelligence mappe les champs suivants de Qualys :
| Champ source de Qualys | Type de données |
|---|---|
| networkInterfaceListData.networkInterface[i].macAddress | String |
| assetUUID | String |
| hardware.category | String |
| lastModifiedDate | String |
| assetName | String |
| address | String |
| lastLocation.name | String |
| hardware.manufacturer | String |
| hardware.model | String |
| operatingSystem.osName | String |
| operatingSystem.version | String |
| assetType | String |
| tagList.tag.tagName | String |
| agent.version | String |
| userAccountListData.userAccount.name | String |
| reference | String |
| launch_date | Date/Time |
| qid | String |
| title | String |
| sévérité | String |
| port | String |
| cve_id | String |
| category | String |
Intégration ServiceNow
The ServiceNow plugin retrieves asset data from the ServiceNow alm_asset table.
Required Configuration Parameters
- ServiceNow URL: URL d’instance de la plateforme ServiceNow
- Username: Nom d'utilisateur de l'instance ServiceNow
- Password: Mot de passe de l'instance ServiceNow
Device Attributes
Device Intelligence cartographie les champs suivants de ServiceNow :
| Champ source ServiceNow | Type de données |
|---|---|
| ci.mac_address | String |
| sys_id | String |
| model_category.name | String |
| sys_updated_on | String |
| display_name | String |
| ci.ip_address | String |
| ci.location.name | String |
| ci.manufacturer.name | String |
| model.name | String |
| serial_number | String |
| asset_tag | String |
| assigned_to.user_name | String |
| sys_created_by | String |
| ci.sys_class_name | String |
| ci.sys_class_name.os_version | String |
Intégration Infoblox
Le plugin Infoblox récupère les données de location DHCP actives depuis la plateforme Infoblox.
Required Configuration Parameters
- Infoblox URL: URL d’instance de la plateforme Infoblox
- Username: Nom d'utilisateur pour l'instance Infoblox
- Password: Mot de passe pour l’instance Infoblox
Device Attributes
Device Intelligence cartographie les champs suivants d’Infoblox :
| Champ source Infoblox | Type de données |
|---|---|
| hardware | String |
| address | String |
| client_hostname | String |
| server_host_name | String |
| nom d'utilisateur | String |
| discovered_data.os | String |
| discovered_data.device_location | String |
| discovered_data.device_model | String |
| discovered_data.device_vendor | String |
| discovered_data.device_type | String |
Intégration Microsoft Entra ID
Le plugin Microsoft Entra ID récupère des données gérées périphérique depuis Microsoft Entra ID.
Required Configuration Parameters
- Tenant ID: Tenant ID of the Microsoft Entra ID platform
- Client ID: ID Application (client)
- Client Secret: Valeur secrète du client
Device Attributes
Device Intelligence mappe les champs suivants à partir de Microsoft Entra ID :
| Champ source Entra ID | Type de données |
|---|---|
| ethernetMacAddress | String |
| id | String |
| lastSyncDateTime | String |
| operatingSystem | String |
| osVersion | String |
| deviceCategoryDisplayName | String |
| userDisplayName | String |
| model | String |
| manufacturer | String |
| serialNumber | String |
Intégration des éclaireurs
Le plugin Forescout récupère les données d'inventaire des périphériques découvertes par la plateforme Forescout.
Required Configuration Parameters
- Forescout Host: URL de base de la plateforme Forescout (par exemple, https://<instance>). N’incluez pas de barres ou de chemins traînants.
- API Token: Jeton Bearer utilisé pour authentifier les requêtes API.
- SSL Validation: Activez pour valider les certificats SSL (par défaut). Désactivez uniquement pour les environnements de test.
Device Attributes
Device Intelligence cartographie les champs suivants de Forescout :
| Champ Source Forescout | Max Length | Longueur minimale |
|---|---|---|
| ip_addresses[0] | — | — |
| adresses_mac[0] | — | — |
| rem_os | 128 chars | 2 caractères |
| rem_vendor | 64 caractères | 2 caractères |
| rem_category | 32 caractères | 2 caractères |
| id | 128 chars | 2 caractères |
Intégration SentinelOne
Le plugin SentinelOne récupère les données des périphériques managés depuis SentinelOne.
Required Configuration Parameters
- Base URL: URL de base de l'URL de la console SentinelOne.
- API token: Jeton Bearer utilisé pour authentifier les requêtes API.
Device Attributes
Device Intelligence mappe les champs suivants depuis SentinelOne :
| Champ source SentinelOne | Type de données |
|---|---|
| source_id | String |
| nom d'hôte | String |
| ip | String |
| mac_address | String |
| os | String |
| os_version | String |
| category | String |
| type | String |
| serial_number | String |
| manufacturer | String |
| model_name | String |
| location | String |
| lastseen | String |
| tags | Liste[str] |
Intégration de Tenable
Le plugin Tenable récupère les données des périphériques gérés depuis Tenable.
Required Configuration Parameters
- Tenable URL: URL de base pour Tenable.
- Tenable Secret key: Nom d'utilisateur pour Tenable.
- Tenable Access key: Mot de passe pour Tenable.
Device Attributes
Device Intelligence mappe les champs suivants depuis Tenable :
| Champ source Tenable | Type de données |
|---|---|
| ipv4[i] | String |
| mac_address[i] | String |
| hostname[i] | String |
| id | String |
| site_id | String |
| last_seen | String |
| created_at | String |
| operating_system[i] | String |
| serial[i] | String |
| modèle[i] | String |
| has_agent | Boolean |
| utilisateur[i] | String |
| plugin_id | Integer |
| plugin_name | String |
| sévérité | Integer |
| cve[i] | Array<String> |
| plugin_family | String |
| family | String |
| identifiant d'actif (tirets supprimés) | String |
| temps d’exécution du pull | String |
| vrai | Boolean |
| attributes[i].attribute_value | String |
Les champs marqués [i] sont renvoyés sous forme de liste dans la charge utile Tenable ; le plugin prend le premier élément.
Intégration de Kaseya VSA
Required Configuration Parameters
- Kaseya VSA URL: Base URL for Kaseya VSA tenant.
- API Credentials: identifiants API pour accéder au locataire Kaseya VSA
Device Attributes
Device Intelligence mappe les champs suivants à partir de Kaseya VSA :
| Champ source Kaseya VSA | Type de données |
|---|---|
| Nom | String |
| LocalIpAddresses[].IpV4 | String |
| LocalIpAddresses[].PhysicalAddress | String |
AssetInfo[System].CategoryData.Manufacturer → repli : Type | String |
| Description | String |
| ClientVersion | String |
| AssetInfo[0].CategoryName | String |
| Type | String |
| Nom du groupe | String |
| Identifiant | String |
| AssetInfo[BIOS].CategoryData[« Numéro de série »] | String |
| AssetInfo[System].CategoryData.Model | String |
| Tags | List |
Intégration SuperOps
Required Configuration Parameters
- SuperOps API URL: Base URL for SuperOps tenant
- Customer Subdomain: nom du sous-domaine
- API Token: jeton d'API pour l'instance SuperOps
Device Attributes
| Champ source SuperOps | Type de données |
|---|---|
| assetId | String |
| hostName | String |
| primaryMac | String |
| gateway | String |
| loggedInUser | String |
| serialNumber | String |
| manufacturer | String |
| model | String |
| platform | String |
| platformVersion | String |
| assetClass | String |
| site | String |
| lastCommunicatedTime | String |
Intégration CrowdStrike
Configuration Parameters
- CrowdStrike API Base URL: Base URL for CrowdStrike tenant.
- Client (Application) ID: ID client de l'API client CrowdStrike Falcon.
- Client Secret: secret client de l'API client CrowdStrike Falcon.
Device Attributes
| Champ source CrowdStrike | Type de données |
|---|---|
| device_id | String |
| nom d'hôte | String |
| mac_address | String |
| local_ip | String |
| last_login_user | String |
| last_seen | String (ISO 8601, UTC) |
| chassis_type_desc | String |
| product_type_desc | String |
| system_manufacturer | String |
| system_product_name | String |
| serial_number | String |
| os_version | String |
| site_name | String |
| tags | Liste[str] |

