Documentation Index

Fetch the complete documentation index at: https://docs.safe.security/llms.txt

Use this file to discover all available pages before exploring further.

Qualys Asset Management Connector Guide

Prev Next

Qualys Asset Management is a cloud-based solution that detects vulnerabilities on all networked assets including servers, network devices, peripherals, and workstations. The Balbix integration with Qualys Asset Management ingests on-prem and cloud infrastructure assets, associated vulnerabilities, software entities, configured operational and business information, and controls assessment information (if configured) discovered by Qualys Asset Management.

Balbix leverages AI to aggregate, normalize, and deduplicate ingested data, along with information integrated from your existing IT and cybersecurity tools. This creates a unified view of your entire asset inventory, including vulnerabilities and their business and operational context. Balbix’s AI models then analyze this data to provide insights such as deployment gap analysis, risk-based vulnerability prioritization (with detailed ranking and scoring), and risk quantification. This process delivers a comprehensive assessment of risk, whether for a single asset, groups of assets, or your entire enterprise, enabling more informed and effective security decisions.

Integration Summary

The table below provides information about the integration type, asset types, and data types that are fetched by the Balbix connector for Qualys Asset Management.

Integration Type

Fetch: An inbound API integration used to fetch assets, vulnerabilities, control assessment information, and related metadata such as tags.

Types of Assets Fetched

Infrastructure devices such as servers, virtual machines, desktops, laptops, networking, IoT.

Types of Data Fetched

Asset names (e.g., NetBIOS, DNS), hardware information (e.g., manufacturer, serial number), processor information, open port information, location information, interface information (MAC address, IP address), OS information, BIOS information, tags (flat and hierarchical), software information, system status such as reboot pending, vulnerabilities (e.g., CVEs, misconfigurations), timestamps such as “last observed,” control assessment findings.

Note: Availability of specific fields, such as OS details, may depend on the Qualys Asset Management implementation and whether a Qualys host-based agent has been deployed or not.

Prerequisites

Authentication to your Qualys account with valid Qualys credentials is required for making requests to Qualys API Server endpoints.

Create and Configure the Connector

After you have completed the prerequisites, follow these steps to create and configure your Balbix connector for Qualys Asset Management.

Step 1: Select the Connector

Start by selecting a connector using the steps outlined below:

  1. Go to Data Sources from the left navigation bar.

  2. In the Connectors table, click + Add Connector.

  3. Click Select a Connector to Configure to expand the window and view the list of available connectors.

  4. Click the + icon on the Qualys Asset Management tile.

  5. Click Next to configure the connector.

Step 2: Configure the Connector

Configure the connector using the steps outlined below.

  1. Fill in the required configuration fields.

    Instance Name

    Qualys API Server URL

    Enter the base API URL of the server where information will be fetched (e.g., https://qualysapi.qualys.com). Make sure the authorized user for this account has the necessary privileges to access the API.

    Qualys Account Username

    Enter the username for the user account with the necessary permissions to fetch assets and vulnerabilities.

    Qualys Account Password

    Enter the password for the user account with the necessary permissions to fetch assets and vulnerabilities.

    Qualys Asset Management API Filter

    Asset Last Seen Days Filter

    Ingest Vulnerabilities

    Choose this option to enable the ingestion of both inventory and vulnerability data. However, it is recommended to ingest inventory data separately and use the Qualys VMDR connector for vulnerability ingestion, as the VMDR API provides more detailed vulnerability information.

    Note: The Qualys Asset Management API does not include vulnerability status. If you opt to ingest vulnerabilities, the connector will be unable to exclude ignored or disabled vulnerabilities.

  2. Click Test Connection.

Step 3: Schedule the Connector

Step 4: Review Connector Details

API Reference Documentation

To learn more about the Qualys Asset Management API, see the references listed below: