Qualys
Integrate Qualys with Cloudaware to enrich CMDB with vulnerability data and scan coverage, and to drive agent lifecycle via Breeze.
info
- Audience: Cloudaware administrators, SecOps teams, vulnerability management teams, and cloud operations teams
- Outcome: Qualys vulnerability data, scan dates, vulnerability counts, and related risk context are available in CMDB for coverage review, remediation planning, and reporting
Capabilities
The integration supports:
- Read-only discovery of Qualys vulnerability data, scan dates, and vulnerability counts for compute configuration items
- Relationship mappings between Qualys vulnerability data, Cloudaware Applications, and assets in the CMDB
- Search and reporting for Qualys data using CMDB Navigator, CMDB list views, and reports
- Optional Qualys agent lifecycle management through Breeze Agent, where configured
Prerequisites
Before you begin, make sure you have:
- Access to a Cloudaware account.
- A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
- Qualys API URL with the correct platform identifier.
- Qualys username and password with read access (Reader role).
- Additional Qualys permissions if Cloudaware will manage agent lifecycle actions through Breeze.
Add a Qualys Account to Cloudaware
- In Cloudaware, go to Admin.
- Find Qualys, then click + ADD.
- Enter the following values:
- Name: Enter a display name for the Qualys integration.
- API URL: Enter the Qualys API URL with the correct platform identifier.
- Username: Enter the Qualys username.
- Password: Enter the Qualys password.
- Click Save.
- Confirm that the integration status indicator is green.
tip
Allow the initial discovery cycle to complete after enabling the integration.
View Qualys Data in CMDB
- In Cloudaware, open CMDB Navigator.
- In the left pane, select QUALYS.
- Open compute CI records to review Qualys fields such as last scan date and vulnerability counts.
- Review vulnerability records in CMDB.
Supported Objects & Fields
The following objects may have Qualys data in Cloudaware CMDB:
| CMDB Object | API Name |
|---|---|
| AWS EC2 Instance | CA10__CaAwsInstance__c |
| Azure Virtual Machine | CA10__CaAzureVirtualMachine__c |
| Azure VM Scale Set Instance | CA10__CaAzureVmScaleSetInstance__c |
| Google GCE Instance | CA10__CaGoogleGceInstance__c |
| Cloudaware Physical Server | CA10__CaPhysicalServer__c |
| vCenter Virtual Machine | CA10V__CaVCenterVirtualMachine__c |
Cloudaware also ingests or calculates the following fields based on Qualys scan data:
| Field | API Name |
|---|---|
| Last Scan Date | CA10__lastScanDate__c |
| Last Scan Result | CA10__nessusLastScanResult__c |
| Critical Vulnerabilities Count | CA10__vulnerabilityCountOpenCritical__c |
| High Vulnerabilities Count | CA10__vulnerabilityCountOpenHigh__c |
| Medium Vulnerabilities Count | CA10__vulnerabilityCountOpenHigh__c |
| Low Vulnerabilities Count | CA10__vulnerabilityCountOpenLow__c |
Troubleshooting
note
Initial data collection may take time to complete.
Authentication Failed or Integration Shows Red Status
- Verify that the Qualys API URL uses the correct platform identifier.
- Confirm that the Qualys username and password are valid and active.
- Check that the Qualys user has read access to the vulnerability data Cloudaware must collect.
- Re-enter the credentials by editing the integration in Cloudaware.
Qualys Data Is Missing
- Allow the initial discovery cycle to complete.
- Confirm that the expected assets and vulnerability results are available in Qualys.
- Verify that the Qualys user has access to the missing assets, scan results, and vulnerability data.
- In CMDB Navigator, open relevant AWS EC2 instances records to view Qualys-related data (the Qualys section on the Details tab or the Scans tile on a CI)
Agent Lifecycle Actions Do Not Run
- Confirm that Qualys agent lifecycle management is configured in Cloudaware.
- Verify that the Qualys user has the additional permissions required to register or deregister agents.
- Confirm that Breeze is installed, healthy, and able to reach the target hosts.
Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name and a brief description of the issue.
Reconfigure or Remove the Integration
warning
To rotate credentials or update API settings, edit the existing integration instead of deleting and re-creating it.
Update the Integration Details
- Go to Admin.
- Select Qualys.
- Select the specific integration.
- Open the three-dot menu (⋮), then click Edit.
- Update the required fields.
- Click Save.
Remove the Integration from Cloudaware
- Go to Admin.
- Select Qualys.
- Select the specific integration.
- Open the three-dot menu (⋮), then click Delete.
- Confirm the deletion if prompted.
Security Notes
- Use a dedicated Qualys service account with the minimum permissions required for vulnerability discovery.
- Grant agent lifecycle permissions only when Cloudaware must manage Qualys agent registration or deregistration.
- Avoid using a personal administrator account for long-running integrations.
- Store Qualys credentials only in approved credential stores and avoid sharing them through tickets, chat, or documentation.
- Rotate Qualys credentials according to your organization's credential-rotation policy and immediately after suspected exposure.
- Review Qualys account permissions regularly to confirm that Cloudaware can access only the vulnerability data and agent actions required for the integration.
- Update the Cloudaware Qualys integration immediately if the Qualys password is reset, revoked, or replaced.