icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Qualys Technology Add-on (TA) for Splunk
SHA256 checksum (qualys-technology-add-on-ta-for-splunk_1114.tgz) 9b251179721880d8650e1cee9f702ed3dd6e8f3018e8ec045f87e14ba16422f5 SHA256 checksum (qualys-technology-add-on-ta-for-splunk_1113.tgz) f055b59be86dcdad9b5b310c8b9360b3f4b8b3cef3a78807feaf335a98152c21 SHA256 checksum (qualys-technology-add-on-ta-for-splunk_1112.tgz) 20f0fa96ab7ba62437018c1207233c593ee220a8e1da507ee0f642c50f696709 SHA256 checksum (qualys-technology-add-on-ta-for-splunk_1111.tgz) b20330cc10d606d31d79f5378b1c9daa74d461499830c37e9c66dd8dad31d6f4 SHA256 checksum (qualys-technology-add-on-ta-for-splunk_1110.tgz) ad1f0dfc16bb3022e35c99db23a65b15974a993aa0a6d576681cf354d4985a70 SHA256 checksum (qualys-technology-add-on-ta-for-splunk_11015.tgz) 1e0ebf460fc5069e3246b0cbe06416cbe1480cea46c9e41db9d3bb14d41be065 SHA256 checksum (qualys-technology-add-on-ta-for-splunk_11014.tgz) 3fc75381001a569367d29f8ac456d5adb4b23302bb3c44284714d264b7d74585 SHA256 checksum (qualys-technology-add-on-ta-for-splunk_11012.tgz) d3f44a7c7d7fbdb75cd216441714c6979a6b6a1a9008144bf815288056622ec7 SHA256 checksum (qualys-technology-add-on-ta-for-splunk_11011.tgz) 255ecae45fd8c30e242210b33873cdc0b97a9ab685a3b87de7a9f97914ef1459 SHA256 checksum (qualys-technology-add-on-ta-for-splunk_11010.tgz) e889d42aad001a5b6e70ad36385b6b0d91044de5d9cb2ebade85b269469b9638 SHA256 checksum (qualys-technology-add-on-ta-for-splunk_1109.tgz) 937d2b728aba5da79d2807a0fc87c176d3e75ea1ff5878d2dab3545373f44283 SHA256 checksum (qualys-technology-add-on-ta-for-splunk_1108.tgz) fb7a9200b61b640c68c43b9f679962836145f8700653c01db66592613d0ac476 SHA256 checksum (qualys-technology-add-on-ta-for-splunk_1107.tgz) 4e03f9370eaf2a0abbeab206838c5de5f96618fe6c75ef04d2dad5f980e2bc90 SHA256 checksum (qualys-technology-add-on-ta-for-splunk_1106.tgz) 220b8089b1489c8741cd9673b613ef1d7d8f77f27ef91e374625b7bc62c1ac17 SHA256 checksum (qualys-technology-add-on-ta-for-splunk_1105.tgz) 0a879d61f3dfe1a4be112be871a5ab85523fe16098e8d9aae139ed27e454560e SHA256 checksum (qualys-technology-add-on-ta-for-splunk_1104.tgz) 482d5a80370a77616c3053e6822f3f5e8d7c2a86284be3f4e66b045f75339967 SHA256 checksum (qualys-technology-add-on-ta-for-splunk_1103.tgz) 51cea2b224cd8c1185b7dae675935b619b83fe328bd8896ce3f1b1fccae13bcb SHA256 checksum (qualys-technology-add-on-ta-for-splunk_1102.tgz) 630af8c454c6e7b71171588d6e0e1fa669dc3d6a7db1f39a002773d07bc507b6 SHA256 checksum (qualys-technology-add-on-ta-for-splunk_1101.tgz) c2077bbbb0792468a2a3522c40bb8a2e16cbbe3304d8f5d740c82da624404d9f SHA256 checksum (qualys-technology-add-on-ta-for-splunk_191.tgz) da1939c25ccba7c2d1daa286c7bef077582f9e00da565b0f850dfcd389923bfb SHA256 checksum (qualys-technology-add-on-ta-for-splunk_190.tgz) 004c3dc21fa16d07447edb59426cb3311b365fa421e997b2af867212e0ec732b SHA256 checksum (qualys-technology-add-on-ta-for-splunk_1811.tgz) 76b8e1f9212e9b8de831afcd1d0bf7eed3373bdbbf573f1701495d106666d4c2 SHA256 checksum (qualys-technology-add-on-ta-for-splunk_1810.tgz) 3f0127eee6573ba83884c006fa0d80e36c97154b71d8ecac056702fbcf4f2b7b SHA256 checksum (qualys-technology-add-on-ta-for-splunk_189.tgz) 7a5dcb626d2ebb0dd85032d65275484bcb76f47fcd03760f20fea74e137d1092 SHA256 checksum (qualys-technology-add-on-ta-for-splunk_188.tgz) 47365c531015e8422685701774c1e9d3d08acd97b1ed003d88ce0e9d6096c6ce SHA256 checksum (qualys-technology-add-on-ta-for-splunk_187.tgz) fad5242f30e080a7c798b214245bfa6aa5c18cc190b1fe3644f3b2db8ef41eff SHA256 checksum (qualys-technology-add-on-ta-for-splunk_186.tgz) 05ee81e0b6e36974a9a04be863ce7afd4149270ce55e9db46d03fe67441a7929 SHA256 checksum (qualys-technology-add-on-ta-for-splunk_185.tgz) 81d24b362dfe79ba8c221945359fb587308c905585375d7ee4cc79eea1416edc SHA256 checksum (qualys-technology-add-on-ta-for-splunk_184.tgz) 1738bebc80fb4eee286dc5a181f25e99e01c61f984784005ce31a18b2c72e29c SHA256 checksum (qualys-technology-add-on-ta-for-splunk_183.tgz) 561a3f287ed3590c128f0fbf7a116644b84ff8c9fcb12d637aed06f54103e368 SHA256 checksum (qualys-technology-add-on-ta-for-splunk_182.tgz) cc97839d2975e38b1862250c1f2f27680ef70d2c805f735d1c165edcaaffec77 SHA256 checksum (qualys-technology-add-on-ta-for-splunk_181.tgz) 7876c0a1269c79abc9f444c8d74acbab61c0f8257fb55afbd6fee5667156cc0c SHA256 checksum (qualys-technology-add-on-ta-for-splunk_180.tgz) fc1cf6d49c6786c4e10711c99f82d00bbba63ec5ca1df14febca2eeebac53fa6
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

Qualys Technology Add-on (TA) for Splunk

Splunk Cloud
Overview
Details
The Qualys Technology Add-on (TA) for Splunk is a Technology Add-On for Qualys Cloud Platform data. It fetches Vulnerability Management (VM), Web Application Scanning (WAS), Policy Compliance (PC), Container Security(CS), File Integrity Monitoring(FIM), Endpoint Detection & Response (EDR), Security Enterprise Mobility (SEM), Activity Log, KnowledgeBase (KB), Policy Compliance Reporting Services (PCRS), Cyber Security Asset Management(CSAM) and Certview data using modular input and indexes it which then can be searched using the Search app, Splunk Enterprise Security app or the Qualys VM App, WAS App or PC App, EDR App, FIM App, CS App , Policy Compliance Reporting Services (PCRS) App, Cyber Security Asset Management(CSAM) App and Certview App for Splunk Enterprise.
Support and resources

For documentation please see: https://community.qualys.com/docs/DOC-4876

Support

In case any assistance is needed, please visit https://www.qualys.com/forms/contact-support/

Release Notes

Version 1.11.4
March 27, 2024

Added Multithreading support in EDR for data ingestion
Retry logic enhancement for EDR Module
Bug fixes for VM Module

Version 1.11.3
Feb. 21, 2024

-Debugging enhancement for VM Detection Data

Version 1.11.2
Jan. 22, 2024

-Added feature on the TA setup Page to let the user terminate the running PID for the respective data input.
-Enhanced configuration for the VM Detection Settings.

Version 1.11.1
Nov. 30, 2023
  • Added "Host IDs" field and "Enable to preserve Host Asset API response" checkbox under VM Detection - Advanced Settings in VM Detection Settings in TA setup page.
Version 1.11.0
Nov. 6, 2023
  • Added new data inputs for Cyber Security Asset Management (CSAM) and Certview
  • User can now fetch the Assets data into Splunk as well as certificate information with the help of newly added data inputs
  • Minor bug fixes and improvements
Version 1.10.15
Sept. 26, 2023
  • Enhancement in host detection data regarding TruRisk factors and additional information
Version 1.10.14
Sept. 20, 2023

-Minor bug fixes and enhancements

Version 1.10.12
July 19, 2023
  • Minor bug fixes and enhancements
Version 1.10.11
June 6, 2023
  • Bug fixes and enhancements
Version 1.10.10
April 20, 2023
  • Fix provided for the TruRisk factors parsing for the "host_detection" data input.
Version 1.10.9
March 24, 2023
  • Enhanced data pulling efficiency for Qualys PCRS data input
  • Minor Bug fixes and enhancements
Version 1.10.8
Feb. 24, 2023
  • User can now fetch TruRisk Fields for Host Detection (ARS, ACS, ARS_FACTORS, QDS and QDS_FACTORS)
  • Enhanced configuration of Policy Compliance Reporting Service Settings in the setup page
  • Minor enhancements and bug fixes
Version 1.10.7
Jan. 20, 2023
  • Added Truncation Limit field under Policy Compliance Reporting Service Settings to truncate evidence field in TA setup page.
    Note: The Truncation Limit field defines the number of lines in the evidence field. For example, if you specify the truncation limit as 500, then only 500 lines are visible in the evidence section. If you do not want to restrict the evidence field, leave the truncation limit blank or specify 0.
Version 1.10.6
Nov. 4, 2022
  • Improvement in data ingestion performance for PCRS data input
  • Parsing of additional Host fields for VM detection
  • Minor bug fixes and logging improvements
Version 1.10.5
Sept. 6, 2022
  • Extended the compatibility with Splunk 9.0
  • Enhanced the VM and KB data input for parsing and ingesting of additional fields data into Splunk
  • Minor fixes and improvements
Version 1.10.4
June 30, 2022
  • TA can now fetch and parse CLOUD_PROVIDER_TAGS information
  • Minor enhancements in the Host Detection data pulling

Note: Not compatible with Splunk 9.0

Version 1.10.3
June 3, 2022
  • Fix for STIG Reference Number in Policy Posture data
Version 1.10.2
May 23, 2022
  • Improvements in logging and minor enhancements
Version 1.10.1
April 19, 2022
  • Integration of the Qualys Policy Compliance Reporting Service (PCRS) with Splunk TA
  • PCRS improves the data fetching of the huge data from the Qualys Cloud
  • PCRS fetches data continuously in the streaming manner hence, millions of assets and postures can be pulled quickly as compared to
    legacy PC
  • Minor bug fixes and improvements
Version 1.9.1
Dec. 21, 2021
  • Minor bug fixes and improvements
Version 1.9.0
Dec. 14, 2021
  • Integration of the Qualys Secure Enterprise Mobility with Splunk TA
  • User can view Diagnosis, Consequence, and Solution information in Knowledgebase data in Splunk by enabling it from the TA setup page
  • Minor bug fixes and enhancements
Version 1.8.11
Nov. 19, 2021

Bug fixes
Users can now ingest detected service names in the event along with TCP/UDP ports

Version 1.8.10
Oct. 28, 2021

Users can now ingest detected service names in the event along with TCP/UDP ports

Version 1.8.9
July 15, 2021

ATTENTION PLEASE!
1) Changes to the TA setup page for Qualys API credentials: We have added a realm for Qualys API credentials that get stored in 'passwords.conf' file. When you upgrade to TA 1.8.9, please re-enter the Qualys API credentials. The TA won't be able to access the Qualys API credentials until then. We recommend you empty the cache of your browser and do a hard reload before entering the credentials.

2) The Indication of Compromise (IOC) data inputs rebranded as Endpoint Detection and Response (EDR) data inputs: From this version, the TA will show a deprecation warning in the TA log for IOC data input. Please disable and delete earlier IOC data input and add a new EDR data input. You can use the new Qualys EDR App for Splunk Enterprise.

Other Fixes:
1) Fixed 400 Bad Request issues for certain pagination calls for Container Security.
2) Fixed incomplete API response XML file issue for Policy Compliance.
3) Added milliseconds in the checkpoint file for FIM data inputs to be compliant with API.

Version 1.8.8
May 27, 2021
  • FIM data inputs will accept the date format for milliseconds
Version 1.8.7
May 18, 2021
  • Updated CS Images and CS Containers API version to 1.3
  • Added DISA STIG SV values to PC Data Input
  • Minor improvements on the TA setup page
Version 1.8.6
April 8, 2021
  • The processing logic of Policy Compliance posture information has been changed.
  • The logic of XML file processing has been changed.
  • Help text on the data inputs page has been updated.
Version 1.8.5
March 8, 2021

Host and Detection fields to log are now configurable from the TA setup page
Truncate the Results field at the TA side

Version 1.8.4
Dec. 4, 2020
  • Knowledgebase data can now be indexed as well, by enabling the indexing from the TA Setup page, this feature will mainly help in Splunk distributed setup.
  • Container Security image data input has the capability to index image label info.
  • Minor improvements for fields validation on the setup page.
Version 1.8.3
Nov. 6, 2020

Features / Improvements:
Read the VM data input configuration values from 'qualys.conf' instead of the app configuration file
New logic implemented for policy ids distribution for PC data input

Bug Fixes:
VM host summary logged in Splunk even though excluded in the TA setup
WAS summary events were not indexing while WAS data input was running in multi-thread mode
PC Evidence details were not logged in case 'lastUpdated' attribute not present in the API output

Version 1.8.2
Oct. 7, 2020
  • Enhancements to VM Detection Event, moved the Results field to the end of the event
Version 1.8.1
Sept. 9, 2020

-Fix for byte string present in the data ingested for host detection in Splunk version 8.0.0 or higher which uses Python 3 interpreter
-Added support for activity_log data feed in cleanup.py and run.py scripts
-Added validation for Start date while adding/editing data input

Version 1.8.0
July 28, 2020
  • Splunk Cloud Compatibility changes - Setup xml replaced with Setup view. We have also done visualization changes to the Setup page.
  • New data feed - Activity Log. The user activity log that you see on Qualys UI > User > Activity Log, can now ingest.
  • Added Page Size field on the Setup page for CS, FIM, and IOC to control the number of records returned in API calls

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.