Qualys vulnerability management software helps you measure known and unknown risks, prioritize, and communicate risk across vulnerabilities, and patch any device anywhere. For more information, please refer to Qualys documentation.
Integration Method: API
Tables: Vulnerability Finding (2002), Device Inventory Info (5002)
This integration supports the following events.
Event | Description |
---|---|
Vulnerability Report | Retrieves list of detections with their asset name. |
Assets | Retrieves list of asset details. |
This integration supports the following versions.
Qualys Report API version | 2.0 |
Prerequisites
Access to Qualys dashboard with manager with full scope.
Access to the DataBee Console.
Asset must be part of an asset group to retrieve their vulnerabilities.
Configuration Overview
Create API credentials on the Qualys dashboard with required permissions.
Create a user with the required permissions.
Add the Qualys VM feed in the DataBee console with the below parameters.
DataBee Parameter
Qualys VM Report Parameter
Username
Username
Password
Password
Qualys Configuration
Create User
Sign in to the Qualys Dashboard.
Navigate to the Users tab.
Create a new user using the Users > New > User dropdown on the user page.
Fill in the required data in the “General Information” tab. Then Click on User Role.
In the “User Role” tab, fill in the role details and make sure we have allowed access to both API and GUI.
User Role – Manager
Allow access in – GUI, API
Keep the Locale, Options, and Security settings as they are and click Save.
Note:
Permissions mentioned here are the minimum requirements for the data feed.
The new user will be created with a Pending Activation Status. An activation link will be sent via email.
You will receive an email. Store the Platform URL securely as it’ll be required to configure data source later. Click on Activate Your Account.
Enter the OTP Code received in email and click Submit.
You will get the information below, copy the password, and click on the URL. Login with the given username and password.
When you login with a new username and password for the first time, you will redirect to the verification page, verify your information, and click Save.
It will redirect to the “Change Password” window, the user can set a new password and login, and the user will be in active status. We will use the username and password to configure the API integration.
DataBee Configuration
Login to the DataBee UI, navigate to Data > Data Feeds and click the Add New Data Feed button.
Search for the Qualys VM Report and click on it as shown below.
Click on the API Ingest option for collection method.
Enter feed contact information and click Next.
In the configuration page, confirm the following:
Authorization Method: Basic
API Base URL: Identify the API base URL from your platform URL. Refer to this document to identify your base URL
Username: paste the Username generated earlier in email.
Password: paste the Password of the account that was set up earlier.
Event Types: preselected for all the event types that integration pulls.
Click Submit.
Troubleshooting Tips
Ensure that username and password are correct.
If you are unable to login with the temporary password, make sure you have given UI Permission to the User
If certain hosts are missing from the report, verify in the Qualys dashboard that those hosts are assigned to at least one asset group. Only assets associated with asset groups are included in the process.
HTTP 400 Response Code – May include errors such as "The Report Share disk limit for the subscription has been reached" which indicates that the storage quota for saved reports or templates has been exceeded and unused items should be deleted to free up space.