[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-09-04。"],[[["\u003cp\u003eThis document provides instructions on how to configure Google Security Operations to ingest and parse Qualys Scan logs via a Third Party API feed.\u003c/p\u003e\n"],["\u003cp\u003eThe parser extracts data from Qualys Scan JSON logs, normalizes timestamps, and maps the data to the Unified Data Model (UDM) fields.\u003c/p\u003e\n"],["\u003cp\u003eConfiguration requires a Google Security Operations instance, privileged access to the Qualys VMDR console, and the creation of a dedicated API user in Qualys.\u003c/p\u003e\n"],["\u003cp\u003eThe process involves identifying the Qualys API URL, setting up a new feed in Google Security Operations, and specifying parameters like username, secret, API full path, and asset namespace.\u003c/p\u003e\n"],["\u003cp\u003eThe UDM Mapping Table details how specific Qualys log fields are translated and mapped into UDM fields, and the logic used to apply them.\u003c/p\u003e\n"]]],[],null,["# Collect Qualys Scan logs\n========================\n\nSupported in: \nGoogle secops [SIEM](/chronicle/docs/secops/google-secops-siem-toc)\n| **Note:** This feature is covered by [Pre-GA Offerings Terms](https://chronicle.security/legal/service-terms/) of the Google Security Operations Service Specific Terms. Pre-GA features might have limited support, and changes to pre-GA features might not be compatible with other pre-GA versions. For more information, see the [Google SecOps Technical Support Service guidelines](https://chronicle.security/legal/technical-support-services-guidelines/) and the [Google SecOps Service Specific Terms](https://chronicle.security/legal/service-terms/).\n\nThis parser extracts fields from Qualys Scan JSON logs, normalizes timestamps, and maps them to the UDM. It handles various Qualys event types, including generic events and user logins, populating UDM fields with relevant security information and metadata.\n\nBefore you begin\n----------------\n\nEnsure that you have the following prerequisites:\n\n- Google Security Operations instance.\n- Privileged access to Qualys VMDR console.\n\nOptional: Create a dedicated API User in Qualys\n-----------------------------------------------\n\n1. Sign in to the Qualys console.\n2. Go to **Users**.\n3. Click **New** \\\u003e **User**.\n4. Enter the **General Information** required for the user.\n5. Select the **User Role** tab.\n6. Make sure the role has the **API Access** checkbox selected.\n7. Click **Save**.\n\nIdentify your specific Qualys API URL\n-------------------------------------\n\n### Option 1\n\nIdentify your URLs as mentioned in the [platform identification](https://www.qualys.com/platform-identification).\n\n### Option 2\n\n1. Sign in to the Qualys console.\n2. Go to **Help** \\\u003e **About**.\n3. Scroll to see this information under Security Operations Center (SOC).\n4. Copy the Qualys API URL.\n\nSet up feeds\n------------\n\nTo configure a feed, follow these steps:\n\n1. Go to **SIEM Settings** \\\u003e **Feeds**.\n2. Click **Add New Feed**.\n3. On the next page, click **Configure a single feed**.\n4. In the **Feed name** field, enter a name for the feed; for example, **Qualys Scan Logs**.\n5. Select **Third Party API** as the **Source type**.\n6. Select the **Qualys Scan** as the log type.\n7. Click **Next**.\n8. Specify values for the following input parameters:\n - **Username**: enter the username for the dedicated user.\n - **Secret**: enter the password for the dedicated user.\n - **API Full Path** : provide plain Qualys API server URL (for example, `qualysapi.qg2.apps.qualys.eu`).\n - **API Type**: select the scan type you want to ingest.\n9. Click **Next**.\n10. Review the feed configuration in the **Finalize** screen, and then click **Submit**.\n\nUDM Mapping Table\n-----------------\n\n**Need more help?** [Get answers from Community members and Google SecOps professionals.](https://security.googlecloudcommunity.com/google-security-operations-2)"]]