Hi,
I have ingested the qualys data using the Qualys TA addon and enabled the inputs to run once every 24 hours.
Im ingesting the host detection and knowledge logs into Splunk.
The requirement is to create a dashboard with multiple multiselect filters and do the enrichment from our database.
But I found that the data in qualys is different from Splunk logs.
And the inputs is ingesting only a certain amount of data.
My ask is I want to ingest complete data every time the inputs runs , so that I get accurate data and use it in dashboards.
Please help me.
Regards,
Dayal
Hi,
You mean other app?
Hi @Dayalss ,
yes, there are seven apps for Qualys, two of them seem to be related to vulnerabilities.
I'm not a Qualys expert, so I don't know which app is the one for your requirements.
Ciao.
Giuseppe
Hi @Dayalss ,
the Qualys Add-On for Splunk is very useful to ingest and parse Qualys data, but it doesn't contains dashboard to display data.
For this requirement, find another app in splunkbase: apps.splunk.com,
I don't know which is the most accurate for your requirements.
You can use these dashboard as they are or as starting point for your custom dashboards.
Ciao.
Giuseppe
Hi @gcusello ,
I have installed the Qualys Vulnerabilities app , but it does not full fill our requirement.
We need to build custom dashboards , but there is data mismatch.
Need to fix it.
Regards,
Dayal
Hi @Dayalss ,
check other dashboards, I'm almost sure that you'll find what you're searching.
Ciao.
Giuseppe