Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Connector ID | QualysVMLogsCCPDefinition |
| Publisher | Microsoft |
| Used in Solutions | QualysVM |
| Collection Method | CCF |
| Connector Definition Files | QualysVMHostLogs_ConnectorDefinition.json |
| DCR Definition Files | QualysVMHostLogs_DCR.json |
| CCF Configuration | QualysVMHostLogs_PollingConfig.json |
| CCF Capabilities | Basic, Paging |
| Microsoft Learn | View on Learn |
The Qualys Vulnerability Management (VM) data connector provides the capability to ingest vulnerability host detection data into Microsoft Sentinel through the Qualys API. The connector provides visibility into host detection data from vulerability scans.
This connector ingests data into the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
QualysHostDetectionV3_CL |
✓ | ✓ | ✓ |
💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.
Resource Provider Permissions:
Custom Permissions:
⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.
1. Connect Qualys Vulnerability Management to Microsoft Sentinel
NOTE: To gather data for Detections based on Host, expand the DetectionList column in the table. To gather data from Qualys VM, you need to provide the following resources
1. API Credentials
To gather data from Qualys VM, you'll need Qualys API credentials, including your Username and Password.
2. API Server URL
To gather data from Qualys VM, you'll need the Qualys API server URL specific to your region. You can find the exact API server URL for your region here
Configure the maximum number of host detection records to retrieve per API call. Recommended: 1000 (Qualys default). Lower values reduce response size and are safer for large environments or slow API servers but require more paginated calls. Higher values increase response size and risk API timeouts, especially on large environments. Values below 500 may cause excessive pagination that exceeds processing limits on large deployments. Timeout limit: The maximum allowed API timeout is 5 minutes (300 seconds). This is the platform maximum and cannot be raised. For large environments, lower the Truncation Limit to keep each API response within this limit.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊