.png)
Qualys Integration Guide
Integrate Qualys security and compliance data with enterprise systems through module-specific REST APIs, asynchronous operations, exports, and selected event notifications.
Qualys integration options at a glance
Qualys provides module-specific REST-style APIs for vulnerability management, asset inventory, compliance, scanning, reporting, and related security operations. APIs may return XML, JSON, CSV, or other documented formats, while scans and report generation can run as asynchronous jobs that require polling. Selected Qualys products support notification or callback capabilities, but webhook coverage is not universal. Martini can authenticate with Qualys using securely stored credentials, schedule incremental retrieval, manage pagination and throttling, poll long-running jobs, transform exported files, and synchronize normalized Assets, Vulnerabilities, Reports, and related objects with downstream systems.
Common Qualys integration patterns
Common Qualys data objects used in integrations
Authentication and security considerations
Module-specific authentication
Qualys authentication varies by product and platform version. Common patterns include HTTP Basic Authentication and session-based login, while some module APIs may document API keys, tokens, or other credentials.
Least privilege and secrets
Use a dedicated Qualys API user with only the roles and subscribed-module permissions required by the workflow. Store credentials, session values, and platform URLs in Martini environment configuration and secrets rather than embedding them in workflow logic.
Operational security
- Do not log Basic Authentication headers, session cookies, or API tokens.
- Use the regional or product-specific Qualys platform URL assigned to the customer.
- Separate credentials and permissions by environment where practical.
- Route authorization failures for operational review instead of repeatedly retrying them.
Operational considerations for Qualys integrations
API limits and pagination
Qualys limits and concurrency constraints can vary by platform, subscription, module, and account. Use documented pagination and filters, bounded concurrency, request pacing, and backoff for throttling.
Asynchronous operations
Scans and report generation may return an operation identifier. Store the identifier, poll at a controlled interval, enforce a maximum duration, and handle failed, cancelled, or expired jobs without submitting duplicates.
Idempotency and checkpoints
Use stable identifiers such as Asset IDs, QIDs, detection IDs, Scan IDs, and Report IDs to correlate downstream records. Persist the last successful cursor, timestamp, identifier, or extraction boundary where supported, and use an overlap window when it is not.
Formats and schema changes
Qualys responses may use XML, JSON, CSV, PDF, or other module-specific formats. Test representative responses, handle XML namespaces and repeated elements, tolerate additive fields, and monitor changes to statuses, pagination, severity values, and authentication responses.
Testing and monitoring
- Test permissions separately for each Qualys module and object.
- Validate completed job statuses before processing results.
- Log correlation identifiers and response metadata without exposing secrets.
- Monitor retry volume, throttling, failed jobs, and incomplete synchronizations.
Why use Martini instead of scripts or point-to-point integrations?
Orchestration instead of isolated scripts
Qualys APIs differ across applications, response formats, authentication conventions, and long-running operations. Martini provides a governed workflow layer for authentication, pagination, polling, mapping, routing, and error handling without coupling every target directly to Qualys.
Reusable integration assets
Teams can separate reusable Qualys API calls, canonical transformations, validation, and target-specific business rules. This supports multiple destinations such as ServiceNow, Splunk, Microsoft Sentinel, Jira, and data stores while preserving source identifiers and audit context.
Controlled APIs and operations
Martini can expose normalized APIs for downstream consumers and can receive confirmed Qualys callbacks through controlled endpoints. Scheduling, checkpoints, retries, monitoring, and environment-specific secrets make ongoing synchronization more maintainable than point-to-point scripts.