Documentation Index

Fetch the complete documentation index at: https://docs.safe.security/llms.txt

Use this file to discover all available pages before exploring further.

Nozomi Networks On-Prem Connector Guide

Prev Next

Nozomi Networks keeps operational technology (OT) cyber resilient with OT network and endpoint visibility along with threat detection. The Balbix integration with Nozomi Networks ingests OT Assets and associated vulnerabilities discovered by Nozomi.

Balbix leverages AI to aggregate, normalize, and deduplicate ingested data, along with information integrated from your existing IT and cybersecurity tools. This creates a unified view of your entire asset inventory, including vulnerabilities and their business and operational context. Balbix’s AI models then analyze this data to provide insights such as deployment gap analysis, risk-based vulnerability prioritization (with detailed ranking and scoring), and risk quantification. This process delivers a comprehensive assessment of risk, whether for a single asset, groups of assets, or your entire enterprise, enabling more informed and effective security decisions.

Integration Summary

This table provides a summary of the Balbix integration for the Nozomi Networks connector.

Integration Type

Fetch: An inbound API integration used to fetch OT assets, associated operating system and vulnerabilities.

Types of Assets Fetched

OT assets.

Types of Data Fetched

Asset names, hardware information, interface information (MAC address, IP address), OS information​ (OS name), BIOS information, system information (CPU manufacturer), vulnerabilities  information (CVE ID, CVE type, CVE exploit status, CVE details), timestamps (CVE creation time, CVE update time).

Prerequisites

To configure the Balbix connector, you must first create Nozomi Networks API credentials with the appropriate permissions. These credentials are required for completing the configuration process. Here are the steps you need to complete:

Create an API Key

To generate an API key from Nozomi Networks:

  1. Log in to the Nozomi Networks portal.

  2. Go to Admin > Other Actions.

  3. Click Edit OpenAPI keys.

  4. Click +Generate.

  5. Enter description and allowed IP addresses. Click Generate.

  6. Copy and save the key name and token securely for later use when configuring the Nozomi Networks connector in Balbix.

    Caution: The key token will not be shown again after the dialog box closes—be sure to save it.

Create and Configure the Connector

After you have completed the prerequisites, follow these steps to create and configure your Balbix connector for Nozomi Network.

Field Mapping

Imported Field

Balbix Field

name

host_name

level

level_tags

ip

ip_address

mac_address

mac_address

os

os_name

vendor

system_manufacturer

os_or_firmware

os_name

serial_number

serial_number

type

tags

zones

tags

product_name

cpu_model_name

node_id

ip_address

cve

cve_id

API Reference Documentation

To learn more about the Nozomi Networks API, see the reference listed below: