Integrations are how Interno gets its data. You pick a tool from the catalogue, save a set of credentials for it, and run a scan; from then on Interno holds the records that tool reports.
This guide covers finding a tool, adding credentials, running and checking scans, editing credentials, and deactivating or deleting a connection.
defence:integration:view), plus Credentials Create to make changesNavigation: Sidebar → Admin → Integrations
Each card shows the tool's logo and name, its category, the kinds of data it brings in, and the status of its most recent scan.
Categories are broad tool classes rather than vendors. Examples include:
| Category | Example tools |
|---|---|
| Endpoint Detection and Response (EDR) | Microsoft Defender ATP, Crowdstrike Falcon, SentinelOne |
| Vulnerability Management, Detection, and Response (VMDR) | Tenable Security Center |
| Security Information and Event Management (SIEM) | IBM QRadar, LogRhythm |
| Identity and Access Management (IDAM) | Microsoft Active Directory |
| IT Service Management (ITSM) | ServiceNow |
| Cloud Security Posture Management (CSPM) | Microsoft Azure CSPM |
| Firewall | Check Point Next Generation Firewalls (NGFW) |
| Patch Management | ManageEngine Patch Manager Plus |
Others in the list include Vulnerability Assessment (VA), Data Loss Prevention (DLP), Web Application Firewall (WAF), Privileged Access Management (PAM), Attack Surface Management (ASM), Extended Detection and Response (XDR), Network Access Control (NAC), Email Security and Container Security.
| Field | Notes |
|---|---|
| Name | Required. Your label for this connection. Only letters, digits, and . _ - are allowed — no spaces, up to 100 characters. It cannot be changed afterwards. |
| Version | Shown only for tools that support more than one version. |
| Authentication Method | Shown only for tools that offer more than one, for example basic authentication or OAuth. Changing it changes the fields below. |
| Tool-specific fields | Whatever that tool needs, such as base URL, instance, username, password, client ID, client secret or token. Required fields are marked with a red asterisk. |
| Use Proxy? | Switch on if Zeron must reach the tool through a proxy; it reveals HTTP Proxy, HTTPS Proxy and No Proxy. |
> Warning: The name is permanent. It identifies this connection everywhere afterwards, including in scan history, and the platform refuses any attempt to rename it later. Choose it carefully — for example defender-prod, not Defender Prod.
> Note: There is no "test connection" button. A connection proves itself by completing a scan, so run one next.
Saved credentials appear as cards in the same panel, newest first, five to a page. Each card shows the credential's name, its non-secret field values, and whether it is active.
Scan status is one of:
| Status | Meaning |
|---|---|
| Processing | The scan is running |
| Completed | The scan finished successfully |
| Failed | The scan did not finish; the card is outlined in red and the scan information holds the error detail |
Navigation: Sidebar → Assets → Asset Inventory
On the Assets Listing tab, open the Source: dropdown and pick the data set your new integration feeds. The count chip beside the dropdown shows how many records Interno now holds.
You can change a saved connection in place — there is no need to delete it and start again.
Two things behave differently in edit mode:
If you click Update without altering anything, Interno tells you there are no changes to update and closes the form.
From the same three-dot Actions menu:
| Action | What it does |
|---|---|
| Deactivate | Stops the connection being used, while keeping it and its history. The card's status icon turns red. |
| Activate | Brings a deactivated connection back into use. |
| Delete | Removes the credential after a confirmation prompt. |
Deleting needs the defence:integration:credentials:delete permission; everything else on that menu needs defence:integration:credentials:create.
Saving failed with a message about the name → The name may contain only letters, digits, and . _ -, with no spaces or other symbols, and must be at most 100 characters.
I want to rename an integration → Names are permanent. The field is disabled on edit and the platform rejects a rename with *Credential name cannot be changed after creation.* To use a different name, add a new credential and delete the old one.
The secret fields are empty when I edit → That is deliberate. Existing secrets are never shown. Leave them blank to keep them, or type a new value to replace one.
The scan shows Failed → Open Scan Information on the card to read the error. Common causes are expired or wrong credentials, a base URL Zeron cannot reach, or the API account lacking permission in the source tool. Fix the cause, use Edit to correct the credentials, then Start Scan again.
Zeron cannot reach a tool on our network → Switch on Use Proxy? when adding or editing the credential and fill in the HTTP Proxy, HTTPS Proxy and No Proxy values.
Saving a new integration was refused with a message about a limit → Some plans cap how many integrations can be active at once. The message names the current count and the cap. Deactivate one you no longer need, or contact your Zeron representative about your plan.
I cannot see the Add Credentials button or the Actions menu → Adding, editing, scanning and activating all require defence:integration:credentials:create, and deleting requires defence:integration:credentials:delete. Ask your administrator.
The Integrations page shows an access-denied screen → Browsing integrations requires defence:integration:view.
No data appears even though the scan completed → Check the Source: dropdown in Asset Inventory — the data may be under a source you have not selected. If the source is missing entirely, the tool returned no records for that data type.
Need more help? Contact support@zeron.one