Ellipse Gradient for Header

Qualys Integration Guide

Integrate Qualys security and compliance data with enterprise systems through module-specific REST APIs, asynchronous operations, exports, and selected event notifications.

Qualys integration options at a glance

Qualys provides module-specific REST-style APIs for vulnerability management, asset inventory, compliance, scanning, reporting, and related security operations. APIs may return XML, JSON, CSV, or other documented formats, while scans and report generation can run as asynchronous jobs that require polling. Selected Qualys products support notification or callback capabilities, but webhook coverage is not universal. Martini can authenticate with Qualys using securely stored credentials, schedule incremental retrieval, manage pagination and throttling, poll long-running jobs, transform exported files, and synchronize normalized Assets, Vulnerabilities, Reports, and related objects with downstream systems.

Integration pointSupported by Qualys?Common use casesHow Martini supports it
REST APIsYesQualys provides module-specific REST-style APIs for Assets, Vulnerabilities, Scans, Reports, Policies, Controls, and other product data. Endpoint structure, response format, and parameters vary by application and platform.Martini can consume the applicable REST API from workflows, map responses into canonical models, apply business rules, and expose normalized APIs to downstream systems.
Bulk, asynchronous, and batch APIsYesScan execution, report generation, and large asset or vulnerability retrieval may use asynchronous jobs, filters, pagination, ID sets, or extraction parameters.Martini can submit jobs, persist job identifiers, poll status at controlled intervals, retrieve results, and handle timeout, failure, and retry paths.
File and report exportsLimitedQualys modules may generate XML, CSV, PDF, or other report and scan-result formats. Availability and formats differ by product and operation.Martini can retrieve generated files, parse XML or CSV, process JSON where provided, archive or distribute PDF output, and map machine-readable results to target systems.
Webhooks and outbound callbacksLimitedSelected Qualys products and integration features provide event or notification capabilities, but universal coverage across objects and modules is not confirmed.Where the target module supports callbacks, Martini can expose an API endpoint or receive the notification through a workflow trigger, then retrieve the authoritative Qualys resource.
AuthenticationYesQualys commonly supports HTTP Basic Authentication and session-based login, while some modules may document API keys, tokens, or other conventions. Roles and subscribed modules control authorization.Martini can store credentials in secrets, authenticate per environment, create or refresh sessions, and route authorization failures without exposing credentials in workflow logic or logs.
GraphQL APIsNot confirmedNo official Qualys GraphQL API was confirmed in the supplied research.Martini can consume GraphQL APIs generally, but a Qualys GraphQL integration should not be assumed or designed without module-specific confirmation.
SOAP APIsNot confirmedNo current official Qualys SOAP API was confirmed. New integrations should use documented REST or module-specific APIs.Martini supports SOAP generally, but this mechanism is not recommended for Qualys without authoritative module documentation.
Database accessNoQualys is a cloud platform and direct customer database access was not identified. Operational and analytics data should come from APIs or supported exports.Martini can write transformed Qualys data to supported databases, but it should access Qualys through documented APIs and exports rather than direct database connectivity.

How Qualys exposes data and business events

Qualys REST APIs

Qualys documents REST-style APIs across multiple applications, including vulnerability management, asset inventory, compliance, scanning, and reporting. The exact endpoints, authentication, response formats, and platform host depend on the selected module.

Martini implementation pattern

Martini implementation pattern: A workflow authenticates against the configured Qualys platform URL, calls the module-specific endpoint, validates the response, maps Qualys objects into a canonical model, and writes or publishes the result to target systems.

Implementation sequence

Load the Qualys platform URL and module configuration
Authenticate with the configured Qualys credential or session pattern
Call the module-specific REST endpoint
Validate the response and capture Qualys identifiers
Map the response into the target data model
Write the result and record the synchronization checkpoint

Asynchronous jobs and batch retrieval

Qualys scans, report generation, and large result retrieval can be asynchronous or require pagination, filtering, ID sets, and extraction controls. A request may return a scan, report, or job identifier rather than final data.

Martini implementation pattern

Martini implementation pattern: The workflow submits the operation, stores the returned identifier, polls at a controlled interval, applies a maximum duration, retrieves completed output, and routes failed or expired jobs to an operational path.

Implementation sequence

Submit the Qualys scan or report operation
Store the returned job, scan, or report identifier
Wait for the configured polling interval
Retrieve and validate the current operation status
Fetch the completed result or exported file
Mark the job complete or route the failure for review

Qualys event notifications

Selected Qualys products and integration features support notification or callback capabilities, but broad webhook coverage across all Qualys objects and modules is not confirmed. Availability must be verified for the specific product and event.

Martini implementation pattern

Martini implementation pattern: Where a callback is available, Martini exposes a controlled API endpoint or workflow trigger, validates the notification, retrieves the authoritative Qualys resource when necessary, and processes the event idempotently.

Implementation sequence

Expose the Martini endpoint for the confirmed callback
Receive and validate the Qualys notification
Authenticate or authorize the incoming request
Retrieve the current Qualys resource when the notification is incomplete
Apply idempotency and business rules
Acknowledge the event and record processing status

Qualys report and file exports

Qualys applications may export reports or scan results as XML, CSV, PDF, JSON, or other module-specific formats. Machine-readable formats are generally more suitable for synchronization than PDF output.

Martini implementation pattern

Martini implementation pattern: A workflow retrieves or receives the documented export, selects the format-specific parser, maps repeated and nested values, validates the resulting records, and delivers the data or archives the original file.

Implementation sequence

Request or retrieve the Qualys export
Identify the documented output format
Parse XML, JSON, CSV, or PDF according to its purpose
Validate required identifiers and values
Map records to the target model
Deliver the transformed data and retain provenance

Common Qualys integration patterns

Pattern 1: Synchronize Qualys vulnerabilities with ServiceNow

When to use this pattern

Use this pattern when security teams need remediation tasks that remain correlated with Qualys detections and affected Assets. It supports incremental retrieval, severity-based routing, and controlled updates rather than creating a new task for every retry.

Integration direction
Qualys
Martini
ServiceNow
Example Mapping
Qualys FieldCanonical FieldTarget Field
QIDvulnerability.identifieru_qualys_qid
detectionIdfinding.identifieru_qualys_detection_id
severityfinding.severitypriority
assetIdasset.identifiercmdb_ci
Martini implementation pattern

A scheduled Martini workflow calls the applicable Qualys Vulnerabilities API, paginates through changed findings, enriches them with Assets, and maps severity and remediation status to ServiceNow tasks. It stores the Qualys detection and ServiceNow task identifiers, applies duplicate checks, and retries only transient API failures.

Martini capabilities used
  • workflows
  • API consumption
  • scheduling
  • data mapping
  • business rules
  • error handling

Pattern 2: Publish Qualys asset inventory to analytics

When to use this pattern

Use this pattern to maintain a normalized inventory for analytics, SIEM correlation, or reconciliation with endpoint and cloud platforms. It is appropriate when Qualys asset data must be combined with tags, operating-system details, and source timestamps.

Integration direction
Qualys
Martini
Splunk
Example Mapping
Qualys FieldCanonical FieldTarget Field
assetIdasset.identifierqualys_asset_id
ipasset.network_addressip
assetTagsasset.tagstags
operatingSystemasset.operating_systemos
Martini implementation pattern

Martini retrieves Assets using documented filters or extraction boundaries, normalizes XML, JSON, or CSV responses, applies tag and lifecycle rules, and sends batches to Splunk. The workflow records a successful checkpoint and uses reconciliation logic when an asset no longer appears in the source extract.

Martini capabilities used
  • workflows
  • API consumption
  • pagination
  • data mapping
  • file processing
  • monitoring

Pattern 3: Orchestrate a Qualys scan or report

When to use this pattern

Use this pattern when an enterprise process needs to request a Qualys scan or report and distribute the completed result to a compliance, security, or reporting platform. It is designed for long-running operations that cannot be treated as a single synchronous request.

Integration direction
Martini
Qualys
Microsoft Sentinel
Example Mapping
Qualys FieldCanonical FieldTarget Field
scanIdoperation.identifierexternal_operation_id
statusoperation.statusevent_status
severityfinding.severityseverity
reportOutputreport.contentevent_data
Martini implementation pattern

A Martini workflow submits the documented Qualys operation, persists the returned identifier, polls with bounded intervals, and retrieves the completed output. It validates status transitions, prevents duplicate submissions after transient failures, transforms the report, and sends relevant findings to Microsoft Sentinel or another target.

Martini capabilities used
  • workflows
  • API consumption
  • asynchronous orchestration
  • business rules
  • data transformation
  • retry handling

Pattern 4: Receive selected Qualys event notifications

When to use this pattern

Use this pattern only when the subscribed Qualys product explicitly supports an HTTP callback for the required event. It reduces polling for supported events while retaining an authoritative retrieval step for complete data.

Integration direction
Qualys
Martini
Jira
Example Mapping
Qualys FieldCanonical FieldTarget Field
eventTypeevent.typeissue.labels
detectionIdfinding.identifierqualys_detection_id
assetIdasset.identifieraffected_asset
severityfinding.severitypriority
Martini implementation pattern

Martini exposes a secured API endpoint for the confirmed callback, validates the incoming event, retrieves the current Qualys object when needed, and maps it to a Jira issue. Idempotency checks use the event or detection identifier, while malformed events and downstream failures follow separate error paths.

Martini capabilities used
  • API exposure
  • workflow triggers
  • API consumption
  • data mapping
  • validation
  • error handling

Applications commonly integrated with Qualys

Qualys data is commonly connected to security operations, service management, analytics, endpoint, cloud, and development platforms. The exact direction and implementation depend on the Qualys modules, permissions, and APIs enabled in the customer environment.

Application Scenario Direction Martini Pattern
ServiceNow Create remediation tasks or incidents from Qualys Vulnerabilities and synchronize asset, detection, and remediation status. Qualys → Martini → ServiceNow A scheduled Martini workflow retrieves Qualys Vulnerabilities and Assets, correlates stable identifiers with existing ServiceNow records, creates or updates remediation tasks, and routes transient failures for retry. Where the Qualys module supports updates, a second flow can send approved status changes back.
Splunk Centralize Qualys vulnerability, asset, and compliance data for security analytics, dashboards, and correlation. Qualys → Martini → Splunk Martini retrieves filtered or incremental Qualys results, converts XML, JSON, or CSV into the ingestion model required by Splunk, enriches records with asset tags, and delivers batches with checkpointing and error handling.
Microsoft Sentinel Provide Qualys findings and asset context for detection, investigation, and incident correlation. Qualys → Martini → Microsoft Sentinel A Martini workflow polls the applicable Qualys APIs, normalizes findings and asset identifiers, applies severity and ownership rules, and sends security events or supporting data to Microsoft Sentinel using the target ingestion interface.
Jira Create development or operational work items for vulnerabilities affecting applications, infrastructure, or cloud assets. Qualys → Martini → Jira Martini maps Qualys QIDs, detection identifiers, severity, affected assets, and remediation guidance to Jira issue fields, stores the Jira issue key for correlation, and optionally processes selected status changes back into the remediation workflow.
Microsoft Intune Compare Qualys asset and vulnerability information with endpoint inventory and device-management data. Qualys → Martini → Microsoft Intune Martini retrieves Qualys Assets and vulnerability context, matches devices using agreed identifiers, applies reconciliation rules, and publishes discrepancies or remediation signals to the relevant Intune-facing process.
Amazon Web Services Correlate Qualys cloud assets and findings with AWS accounts, instances, and tags. Amazon Web Services → Martini → Qualys Martini receives or retrieves AWS inventory context, maps account and resource identifiers to Qualys asset structures where the subscribed Qualys module supports the operation, and separately publishes normalized findings to downstream cloud governance processes.
Microsoft Azure Correlate Qualys cloud asset inventory and findings with Azure subscriptions, virtual machines, and resource metadata. Microsoft Azure → Martini → Qualys A Martini workflow combines Azure resource metadata with Qualys Assets and findings, applies subscription and tag mappings, and sends supported discovery or remediation updates through the applicable Qualys APIs.
Okta Add identity or access context to security operations and remediation workflows where relevant. Okta → Martini → Qualys Martini orchestrates identity-context retrieval and Qualys finding processing, applies ownership or access rules, and sends only the supported updates to the relevant security or remediation process. Object-level Qualys support must be confirmed for the selected use case.

How to build a Qualys integration in Martini

Objective

Configure the Qualys platform URL, target module, API version, response format, and least-privilege authentication details for each environment.

Instructions in Martini

  • Set the regional or product-specific Qualys base URL as environment configuration
  • Store Basic Authentication credentials, session credentials, or module-specific tokens in Martini secrets
  • Record the Qualys module, API version, permissions, and response format
  • Test authentication separately from business processing

Objective

Select a schedule, API request, or confirmed Qualys callback according to the required freshness and the capabilities of the target module.

Instructions in Martini

  • Use a scheduler for incremental asset, vulnerability, or report retrieval
  • Use a workflow start trigger for a confirmed Qualys callback
  • Use an API entry point when another application must initiate the process
  • Define the checkpoint, event identifier, or request correlation strategy

Objective

Call the relevant Qualys API or retrieve the generated export while respecting pagination, filters, rate constraints, and asynchronous status.

Instructions in Martini

  • Call the module-specific REST endpoint
  • Apply documented filters, pagination, ID sets, or incremental boundaries
  • Persist scan, report, or job identifiers for asynchronous operations
  • Use bounded polling and stop after the configured timeout
  • Capture response metadata needed for auditing and troubleshooting

Objective

Coordinate authentication, retrieval, enrichment, routing, and target writes in a maintainable Martini workflow.

Instructions in Martini

  • Separate authentication and retrieval from transformation logic
  • Branch on operation status, response format, severity, or authorization outcome
  • Enrich Vulnerabilities with related Assets, Policies, or Controls when required
  • Use reusable workflow logic for common Qualys API calls
  • Route permanent failures to an operational error path

Objective

Transform Qualys-specific XML, JSON, CSV, or other documented output into a canonical model and the target application schema.

Instructions in Martini

  • Map stable identifiers such as asset IDs, QIDs, detection IDs, scan IDs, and report IDs
  • Normalize severity, status, tags, timestamps, and ownership values
  • Handle XML namespaces, repeated elements, CSV quoting, and module-specific structures
  • Validate required target fields before writing
  • Preserve source identifiers and provenance for reconciliation

Objective

Apply business rules for severity routing, deduplication, lifecycle state, ownership, and incremental synchronization before target updates.

Instructions in Martini

  • Use stable Qualys identifiers to find existing target records
  • Apply severity and asset-tag routing rules
  • Use overlap windows when a reliable change marker is unavailable
  • Prevent duplicate downstream creation during retries
  • Treat authorization and validation errors as non-retryable unless corrected

Common Qualys data objects used in integrations

ObjectTypical UseCommon target systemsMartini handling
AssetsRepresent hosts, IP addresses, cloud assets, inventory items, and asset tags used for exposure and inventory management.ServiceNow, Microsoft Intune, Splunk, Microsoft Sentinel, data warehousesMartini retrieves Assets incrementally or in pages, maps platform-specific identifiers and tags to a canonical asset model, reconciles additions and inactive assets, and persists source-to-target correlations.
VulnerabilitiesRepresent vulnerability findings, QIDs, detections, severity, remediation status, and affected assets.ServiceNow, Jira, Splunk, Microsoft SentinelMartini filters and paginates findings, enriches them with Asset data, applies severity and ownership rules, and upserts downstream findings or remediation tasks using stable identifiers.
ScansRepresent vulnerability, web application, or compliance scans together with status, identifiers, and results.ServiceNow, security operations platforms, reporting storesMartini submits supported scan operations, stores scan identifiers, polls asynchronous status, validates completion, and retrieves or routes results with bounded retries.
ReportsRepresent vulnerability, compliance, asset, or scan reports and generated output.File repositories, Splunk, reporting systems, data warehousesMartini requests or retrieves reports, polls report jobs, parses machine-readable formats, archives human-readable files when required, and records report status and provenance.
PoliciesRepresent compliance or security policies used to evaluate assets and controls.Governance platforms, compliance stores, data warehousesMartini retrieves policy definitions or status where supported, maps policy identifiers and classifications, and synchronizes changes using module-specific filters and permissions.
ControlsRepresent compliance controls, evaluations, exceptions, and assessment results.ServiceNow, GRC platforms, Splunk, Microsoft SentinelMartini transforms control and evaluation responses, preserves policy, asset, and control relationships, and routes exceptions or failed evaluations according to business rules.

Authentication and security considerations

Module-specific authentication

Qualys authentication varies by product and platform version. Common patterns include HTTP Basic Authentication and session-based login, while some module APIs may document API keys, tokens, or other credentials.

Least privilege and secrets

Use a dedicated Qualys API user with only the roles and subscribed-module permissions required by the workflow. Store credentials, session values, and platform URLs in Martini environment configuration and secrets rather than embedding them in workflow logic.

Operational security

  • Do not log Basic Authentication headers, session cookies, or API tokens.
  • Use the regional or product-specific Qualys platform URL assigned to the customer.
  • Separate credentials and permissions by environment where practical.
  • Route authorization failures for operational review instead of repeatedly retrying them.

Operational considerations for Qualys integrations

API limits and pagination

Qualys limits and concurrency constraints can vary by platform, subscription, module, and account. Use documented pagination and filters, bounded concurrency, request pacing, and backoff for throttling.

Asynchronous operations

Scans and report generation may return an operation identifier. Store the identifier, poll at a controlled interval, enforce a maximum duration, and handle failed, cancelled, or expired jobs without submitting duplicates.

Idempotency and checkpoints

Use stable identifiers such as Asset IDs, QIDs, detection IDs, Scan IDs, and Report IDs to correlate downstream records. Persist the last successful cursor, timestamp, identifier, or extraction boundary where supported, and use an overlap window when it is not.

Formats and schema changes

Qualys responses may use XML, JSON, CSV, PDF, or other module-specific formats. Test representative responses, handle XML namespaces and repeated elements, tolerate additive fields, and monitor changes to statuses, pagination, severity values, and authentication responses.

Testing and monitoring

  • Test permissions separately for each Qualys module and object.
  • Validate completed job statuses before processing results.
  • Log correlation identifiers and response metadata without exposing secrets.
  • Monitor retry volume, throttling, failed jobs, and incomplete synchronizations.

Why use Martini instead of scripts or point-to-point integrations?

Orchestration instead of isolated scripts

Qualys APIs differ across applications, response formats, authentication conventions, and long-running operations. Martini provides a governed workflow layer for authentication, pagination, polling, mapping, routing, and error handling without coupling every target directly to Qualys.

Reusable integration assets

Teams can separate reusable Qualys API calls, canonical transformations, validation, and target-specific business rules. This supports multiple destinations such as ServiceNow, Splunk, Microsoft Sentinel, Jira, and data stores while preserving source identifiers and audit context.

Controlled APIs and operations

Martini can expose normalized APIs for downstream consumers and can receive confirmed Qualys callbacks through controlled endpoints. Scheduling, checkpoints, retries, monitoring, and environment-specific secrets make ongoing synchronization more maintainable than point-to-point scripts.

Frequently asked questions

How can Qualys be integrated with enterprise systems?

Qualys can be integrated through its module-specific REST APIs, asynchronous scan and report operations, supported exports, and selected notification or callback capabilities. The exact endpoint, authentication pattern, response format, and event coverage depend on the Qualys application and subscription.

Can Martini integrate with Qualys?

Yes. Martini can consume the applicable Qualys REST APIs, authenticate using securely managed credentials, schedule synchronization, paginate through results, poll asynchronous jobs, process supported exports, and synchronize Qualys data with enterprise applications. Where a Qualys product supports callbacks, Martini can also receive the notification.

Do I need a connector to integrate Qualys with Martini?

No. A dedicated Qualys connector is not required. Martini can integrate with Qualys using its confirmed native REST APIs, authentication methods, supported exports, and module-specific event or callback endpoints.

Is there any extra Lonti cost to integrate Qualys with Martini?

Lonti does not charge an additional per-connector or per-vendor fee to integrate Qualys with Martini. The integration is subject to the provisioned capacity of the Martini environment. Separate costs may apply from Qualys, infrastructure providers, or other third-party systems based on subscriptions, usage, and deployment model.

Which Qualys integration methods should be used?

REST APIs are the primary method for new Qualys integrations. Use module-specific asynchronous APIs for scans, report generation, and large retrievals, and use documented exports when a file-based result is more appropriate. Webhook-style callbacks should be used only after confirming support for the selected Qualys product and event. No official Qualys GraphQL or current SOAP API was confirmed.

Does Qualys support webhooks or callbacks?

Selected Qualys products and integration features support notification or callback capabilities, but universal coverage across Qualys objects and modules should not be assumed. Confirm the target module, event type, authentication requirements, and callback behavior before designing an event-driven workflow.

How does Martini synchronize Qualys data?

Martini can run scheduled or event-driven workflows that retrieve Assets, Vulnerabilities, Scans, Reports, Policies, and Controls, then map and transform them for target systems. Incremental filters, pagination, checkpoints, stable identifiers, overlap windows, and reconciliation logic help control large datasets and prevent duplicate updates.

How does Martini handle Qualys errors, retries, and duplicates?

Martini can distinguish authentication, permission, validation, throttling, transient platform, asynchronous job, and malformed-response failures. Transient conditions can use bounded retries and backoff, while stable identifiers such as QIDs, detection IDs, asset IDs, scan IDs, and report IDs support idempotent updates and duplicate prevention.