Qualys Asset Management is a cloud-based solution that detects vulnerabilities on all networked assets including servers, network devices, peripherals, and workstations. The Balbix integration with Qualys Asset Management ingests on-prem and cloud infrastructure assets, associated vulnerabilities, software entities, configured operational and business information, and controls assessment information (if configured) discovered by Qualys Asset Management.
Balbix leverages AI to aggregate, normalize, and deduplicate ingested data, along with information integrated from your existing IT and cybersecurity tools. This creates a unified view of your entire asset inventory, including vulnerabilities and their business and operational context. Balbix’s AI models then analyze this data to provide insights such as deployment gap analysis, risk-based vulnerability prioritization (with detailed ranking and scoring), and risk quantification. This process delivers a comprehensive assessment of risk, whether for a single asset, groups of assets, or your entire enterprise, enabling more informed and effective security decisions.
Integration Summary
The table below provides information about the integration type, asset types, and data types that are fetched by the Balbix connector for Qualys Asset Management.
Integration Type | Fetch: An inbound API integration used to fetch assets, vulnerabilities, control assessment information, and related metadata such as tags. |
Types of Assets Fetched | Infrastructure devices such as servers, virtual machines, desktops, laptops, networking, IoT. |
Types of Data Fetched | Asset names (e.g., NetBIOS, DNS), hardware information (e.g., manufacturer, serial number), processor information, open port information, location information, interface information (MAC address, IP address), OS information, BIOS information, tags (flat and hierarchical), software information, system status such as reboot pending, vulnerabilities (e.g., CVEs, misconfigurations), timestamps such as “last observed,” control assessment findings. |
Note: Availability of specific fields, such as OS details, may depend on the Qualys Asset Management implementation and whether a Qualys host-based agent has been deployed or not.
Prerequisites
Authentication to your Qualys account with valid Qualys credentials is required for making requests to Qualys API Server endpoints.
Create and Configure the Connector
After you have completed the prerequisites, follow these steps to create and configure your Balbix connector for Qualys Asset Management.
Step 1: Select the Connector
Start by selecting a connector using the steps outlined below:
Go to Data Sources from the left navigation bar.
In the Connectors table, click + Add Connector.
Click Select a Connector to Configure to expand the window and view the list of available connectors.
Click the + icon on the Qualys Asset Management tile.
Click Next to configure the connector.
Step 2: Configure the Connector
Configure the connector using the steps outlined below.
Fill in the required configuration fields.
.png)
.png)
Instance Name
.png)
Qualys API Server URL
Enter the base API URL of the server where information will be fetched (e.g., https://qualysapi.qualys.com). Make sure the authorized user for this account has the necessary privileges to access the API.
.png)
Qualys Account Username
Enter the username for the user account with the necessary permissions to fetch assets and vulnerabilities.
.png)
Qualys Account Password
Enter the password for the user account with the necessary permissions to fetch assets and vulnerabilities.
.png)
Qualys Asset Management API Filter
.png)
Asset Last Seen Days Filter
.png)
Ingest Vulnerabilities
Choose this option to enable the ingestion of both inventory and vulnerability data. However, it is recommended to ingest inventory data separately and use the Qualys VMDR connector for vulnerability ingestion, as the VMDR API provides more detailed vulnerability information.
Note: The Qualys Asset Management API does not include vulnerability status. If you opt to ingest vulnerabilities, the connector will be unable to exclude ignored or disabled vulnerabilities.
Click Test Connection.
Step 3: Schedule the Connector
Step 4: Review Connector Details
API Reference Documentation
To learn more about the Qualys Asset Management API, see the references listed below: