Hello,
Sorry in advance if the question has already been asked, but I couldn't find anything.
I'm currently working with Qualys logs on Splunk. The Qualys API to pull data into Splunk is already configured, but there are several informations that the API does not retrieve, for example software installed on scanned computers.
So the question is, is it possible to add a custom API into Splunk without interfering with the existing official Qualys API ? And is there limitations for programming languages, or maybe it depends on the server on which my Splunk is running ?
Thank you in advance
UPDATE :
Here some complementary information about my issue: the Qualys module I was trying to retrieve on my company's Splunk was Qualys Global AssetView (GAV), which data is not retrieved by the Qualys TA on Splunk. (Thank you anyway @richgalloway !)
So I ended up just creating a simple script to request information through the GAV API and added it as a scripted input on Splunk.
UPDATE :
Here some complementary information about my issue: the Qualys module I was trying to retrieve on my company's Splunk was Qualys Global AssetView (GAV), which data is not retrieved by the Qualys TA on Splunk. (Thank you anyway @richgalloway !)
So I ended up just creating a simple script to request information through the GAV API and added it as a scripted input on Splunk.
It appears as though you are using "API" to mean "TA". If so then, yes, you can create your own TA to retrieve the desired information. Take care, however, to avoid using the same names as the Qualys TA or you risk unexpected behavior.