Nodeware
Nodeware connects your vulnerability scan data into Navigator: asset (device) inventory and the vulnerability findings from each asset’s most recent scan.
At a glance
| Data provided | Devices, Vulnerabilities |
|---|---|
| Authentication | API token |
| Where to configure | Connectors → Add a Connector → Nodeware |
Required permissions
Nodeware uses a single account-level API token — there’s no separate role or permission to grant beyond generating the token itself, and no RBAC-style setup step like Azure’s.
| Credential | Where to find it |
|---|---|
| API Token | Nodeware dashboard → Reports |
Setup
- Log in to your Nodeware account and go to the Reports dashboard.
- Generate (or copy your existing) API token.
- In Navigator, go to Connectors → Add a Connector → Nodeware.
- Enter the API Token.
- Leave Customer Tokens blank to include every customer this token can see, or enter a comma-separated list to limit Navigator to a subset (useful if your Nodeware account manages more customers than you want reflected in Navigator).
- Save. Navigator validates the credentials and enqueues a first sync immediately.
What data this connector provides
- Devices: every asset (internal or external) Nodeware has scanned, across every customer in scope. Includes hostname, a best-effort operating system platform guess, IP address, MAC address, and whether the asset is agent-based or scanned over the network.
- Vulnerabilities: the findings from each asset’s most recently completed scan, including CVE IDs where a finding maps to one, a numeric severity score, and a derived severity category (critical/high/medium/low/info). A finding no longer present in Nodeware’s active CVE list for that asset is automatically marked resolved.
Known limitations
- OS version detail beyond a best-effort platform guess (Windows/Linux/macOS) isn’t populated. Nodeware reports the operating system as a single free-text string with no separate platform/version fields, so anything more specific can’t be reliably derived from it.
- Hardware specs, manufacturer, model, and serial number aren’t available — Nodeware’s asset data doesn’t include them.
- A finding’s first-detected date isn’t populated: Nodeware doesn’t expose one via this connector’s endpoints.