Qualys VMDR
This page explains how to make data from the Qualys Vulnerability Management, Detection and Response integration (Qualys VMDR) appear in the following places within Elastic Security:
- Findings page: Data appears on the Vulnerabilities tab.
- Alert and Entity details flyouts: Data appears in the Insights section of the Alert and Entity details flyouts.
In order for Qualys VMDR data to appear in these workflows:
- Ensure you have read privileges for the following index:
security_solution-*.vulnerability_latest. - Follow the steps to set up the Qualys VMDR integration.
- While configuring the integration, in the Host detection data section, under Input parameters, enter
host_metadata=all. This enables the ingest ofcloud.*fields.
- While configuring the integration, in the Host detection data section, under Input parameters, enter
- (Elastic Stack users) Ensure you're on at least v8.16.
- Make sure the integration version is at least 6.0.0.
Note
You can ingest data from the Qualys VMDR integration for other purposes without following these steps.