Dashboards & Visualizations

Qualys Vulnerabilities Dashboard

Dayalss
Engager

Hi,

I have ingested the qualys data using the Qualys TA addon and enabled the inputs to run once every 24 hours.

Im ingesting the host detection and knowledge logs into Splunk.

The requirement is to create a dashboard with multiple multiselect filters and do the enrichment from our database.

But I found that the data in qualys is different from Splunk logs.

And the inputs is ingesting only a certain amount of data.

 

My ask is I want to ingest complete data every time the inputs runs , so that I get accurate data and use it in dashboards.

Please help me.

 

Regards,

Dayal

Labels (1)
0 Karma

Dayalss
Engager

Hi,

 

You mean other app?

 

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Dayalss ,

yes, there are seven apps for Qualys, two of them seem to be related to vulnerabilities.

I'm not a Qualys expert, so I don't know which app is the one for your requirements.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Dayalss ,

the Qualys Add-On for Splunk is very useful to ingest and parse Qualys data, but it doesn't contains dashboard to display data.

For this requirement, find another app in splunkbase: apps.splunk.com,

I don't know which is the most accurate for your requirements.

You can use these dashboard as they are or as starting point for your custom dashboards.

Ciao.

Giuseppe

 

0 Karma

Dayalss
Engager

Hi @gcusello ,

 

I have installed the Qualys Vulnerabilities app , but it does not full fill our requirement.

 

We need to build custom dashboards , but there is data mismatch.

Need to fix it.

 

Regards,

Dayal

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Dayalss ,

check other dashboards, I'm almost sure that you'll find what you're searching.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...