All Apps and Add-ons

How to connect to Multiple Qualys instances via qualys TA

DavidHourani
Super Champion

Hello dear Splunkers,

I am trying to get information from 2 different Qualys instances, to do so i have set up two different Splunk servers with qualys TA. Everything seems to work fine but I need to get both connections to work from a single Splunk server.

Q1- Is it possible to configure two connections from a single TA-QualysCloudPlatform ? If so, how ?
Q2- If Q1 is impossible, how can I get 2 TA-QualysCloudPlatform to work on the same splunk instance (each one will connect to a seperate Qualys instance) ? I tried copying the TA-QualysCloudPlatform folder and renaming it and also renaming the app but that doesn't seem to work properly..

Any tip would be greatly appreciated..

Regards,
David

james190190
Explorer

Perhaps this might be worth a look: https://github.com/paragbaxi/qualysapi/

0 Karma

nit123
Path Finder

a. Option 1

You can have separate splunk instances and TA installed on each of them to do data pull operations from different qualys instances. As of now, TA does not allow you have multiple server configurations on same setup.

Setup X can have TA with X inputs enabled for Y Qualys Instance.

0 Karma

DavidHourani
Super Champion

Anyone got an answer for that ?

0 Karma

soc9688
New Member

up,
i've got the same problem, but maybe we can try something around the metadatas files?

0 Karma

DavidHourani
Super Champion

Ummm that could work...I tried duplicating configurations and all but nothing seemed to work...let me know if u manage to find a solution please

0 Karma

Marselia
Explorer

@DavidHourani  
I am now struggelign with the same as you did 5 years ago. Did you figure out a way to solve this?

0 Karma

DavidHourani
Super Champion

Hi @Marselia,

Been quite a while, so I don't remember what I ended up doing, but the possible solutions back then were : 

  1. Use a separate HF for each Qualys instance -- Probably not what you want to do.
  2. Edit the bin code in the TA to allow connectivity to multiple instances.
  3. Build your own connector using something similar to this: https://github.com/paragbaxi/qualysapi/
  4. Since the app (https://splunkbase.splunk.com/app/2964/) is built by Qualys, could be worth opening a support ticket and check if they have a modified version of the TA that allows connectivity to multiple Qualys instances.

Hope this helps!

 

0 Karma

Marselia
Explorer

@DavidHourani thank you so much for quick and thorough reply!
I will create a ticket to Qualys through my company, and update this thread if they have a solution for this. 

DavidHourani
Super Champion

You're welcome ! Keep me posted ! 🙂 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...