Documentation Index

Fetch the complete documentation index at: https://docs.safe.security/llms.txt

Use this file to discover all available pages before exploring further.

Nozomi Networks SaaS Connector Guide

Prev Next

Nozomi Networks keeps operational technology (OT) cyber resilient with OT network and endpoint visibility along with threat detection. The Balbix integration with Nozomi Networks ingests OT Assets and associated vulnerabilities discovered by Nozomi.

Balbix leverages AI to aggregate, normalize, and deduplicate ingested data, along with information integrated from your existing IT and cybersecurity tools. This creates a unified view of your entire asset inventory, including vulnerabilities and their business and operational context. Balbix’s AI models then analyze this data to provide insights such as deployment gap analysis, risk-based vulnerability prioritization (with detailed ranking and scoring), and risk quantification. This process delivers a comprehensive assessment of risk, whether for a single asset, groups of assets, or your entire enterprise, enabling more informed and effective security decisions.

Integration Summary

This table provides a summary of the Balbix integration for the Nozomi Networks connector.

Integration Type

Fetch: An inbound API integration used to fetch OT Assets, associated OS and vulnerabilities.

Types of Assets Fetched

IoT and OT assets.

Types of Data Fetched

Asset names, hardware information, interface information (MAC address, IP address), OS information​ (OS name), BIOS information, system information, vulnerabilities information (CVE information), relevant timestamps (e.g., first observed, last observed, tags.

Prerequisites

To configure the Balbix connector, you must first create Nozomi Networks API credentials with the appropriate permissions. These credentials are required for completing the configuration process. Here are the steps you need to complete:

Create User

Create a user to associate with your third-party application.

  1. On the admin navigation bar, click Users in the admin navigation menu.

  2. Enter a name and an email address.

  3. Select the user group where the user should be added.

  4. Click Invite.

Auth Permissions and Roles

Assign a role that grants the necessary permissions and scope within Vantage.

  1. Click Groups in the admin navigation menu.

  2. Double-click the user's group in the table to open the details pane.

  3. Click Details.

  4. Click Role Assignments near the top of the page that appears.

  5. Click Add New.

  6. From the Role drop-down, select the role that grants the permissions appropriate for the actions your application will perform in Vantage. To view a role's permissions, select the role from the drop-down. The matrix of all permissions displays which are granted:

    • Granted permissions are highlighted in green.

    • Revoked permissions are highlighted in red.

  7. If necessary, select an organization in the Restrict to Organization drop-down to limit the access granted to third-party applications associated with users assigned this role.

  8. Click Create.

Create an API Key

To generate an API key from Nozomi Networks:

  1. While logged in as the user who will own the API key, click Profile in the user menu at the top of any Vantage page.

  2. Click API Keys near the top of the page.

  3. Enter a description of the key: Nozomi recommends that the description include the name of the application that will connect using this key. During generation, Vantage assigns a unique name to the key.

  4. If necessary, specify the range of allowed IP addresses. Use the Classless Inter-Domain Routing (CIDR) format, and enter multiple IP ranges in a comma separated list. By default, the range of IPs that can connect to Vantage is controlled by the two Limit IPs Security settings on the General admin page. If you want to specify a different range for your third-party applications, specify them here. Only applications running on IP addresses in the range specified here are permitted to connect using this key.

  5. In the Organizations field, select an organization that will serve as a default for this API key. If an API request using this key doesn’t include an organization, this organization is used by default.

  6. Click Generate to create the key. Vantage generates a key and displays its name, token, allowed IP ranges, and default organization.

  7. Make note of the following details:

    • Key name: A unique value that identifies this key and is used like a username.

    • Key token: A unique value that is used like a password.

      Vantage will never display this information again so be sure to copy it and keep it in a secure location.

    • Allowed IPs: The list of IP address ranges used by the application that will use this key.

Create and Configure the Connector

After you have completed the prerequisites, follow these steps to create and configure your Balbix connector for Nozomi Networks.

Field Mapping

Imported Field

Balbix Field

name

host_name

level

level_tags

ip

ip_address

mac_address

mac_address

os

os_name

vendor

system_manufacturer

os_or_firmware

os_name

serial_number

serial_number

type

tags

zones

tags

product_name

cpu_model_name

node_id

ip_address

cve

cve_id

API Reference Documentation

To learn more about the Nozomi Networks API, see the references listed below: