Qualys Vulnerability Management (via Codeless Connector Framework)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Connectors Index


Attribute Value
Connector ID QualysVMLogsCCPDefinition
Publisher Microsoft
Used in Solutions QualysVM
Collection Method CCF
Connector Definition Files QualysVMHostLogs_ConnectorDefinition.json
DCR Definition Files QualysVMHostLogs_DCR.json
CCF Configuration QualysVMHostLogs_PollingConfig.json
CCF Capabilities Basic, Paging
Microsoft Learn View on Learn

The Qualys Vulnerability Management (VM) data connector provides the capability to ingest vulnerability host detection data into Microsoft Sentinel through the Qualys API. The connector provides visibility into host detection data from vulerability scans.

Tables Ingested

This connector ingests data into the following tables:

Table Transformations Ingestion API Lake-Only
QualysHostDetectionV3_CL

💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.

Permissions

Resource Provider Permissions:

Custom Permissions:

Setup Instructions

⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.

1. Connect Qualys Vulnerability Management to Microsoft Sentinel

NOTE: To gather data for Detections based on Host, expand the DetectionList column in the table. To gather data from Qualys VM, you need to provide the following resources

1. API Credentials

To gather data from Qualys VM, you'll need Qualys API credentials, including your Username and Password.

2. API Server URL

To gather data from Qualys VM, you'll need the Qualys API server URL specific to your region. You can find the exact API server URL for your region here

3. Truncation Limit

Configure the maximum number of host detection records to retrieve per API call. Recommended: 1000 (Qualys default). Lower values reduce response size and are safer for large environments or slow API servers but require more paginated calls. Higher values increase response size and risk API timeouts, especially on large environments. Values below 500 may cause excessive pagination that exceeds processing limits on large deployments. Timeout limit: The maximum allowed API timeout is 5 minutes (300 seconds). This is the platform maximum and cannot be raised. For large environments, lower the Truncation Limit to keep each API response within this limit.


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Connectors Index