A successful integration requires planning and careful execution of pre-integration
tasks. It is essential that you prepare for the integration by performing these procedures. The
Qualys Vulnerability Integration assumes that you are
familiar with and run Qualys Cloud Platform scans in your environment.
Note: Make any necessary configuration changes based on your requirements before running the
integrations.
Important prerequisites
Starting with v10.3, persona and granular roles are available to help you manage
what users and groups can see and do in the Vulnerability Response application. For initial
assignment of the persona roles in Setup Assistant, see Assign the Vulnerability Response persona roles using Setup Assistant. For more information
about managing granular roles, see Manage persona and granular roles for Vulnerability Response.
Validate your instance sizing based on the number of vulnerable items you expect to import.
An undersized instance can lead to long load times. If you do not know the size of your
instance, contact ServiceNow Technical Support.
Use filtering to limit the number of items for initial import and phase your deployment by
adjusting filters in subsequent imports.
Actions to take
- Determine an initial start date
for Host Detection List Import integrations.
Consider setting
the Start time field to a few hours or days in the past. Ideally,
choose the date of the last Qualys scan. The start date can include vulnerabilities
discovered prior to using the vulnerability management solution. Set the earliest start
time used to the start of your scanning cycle. So, if it takes a week before all hosts
are scanned, set this value to a week prior to that time.
- Add users to the roles for admin, sn_vuln.admin, and sn_vul_qualys.admin. For more
information see, Assign a role to a user
Assign a role to a userAssign a role to a user.
-
There is a configured run-as user for each integration record. The default value for
this user is VR.System. Do not change this value.
- If you do not use vulnerability calculators, disable the default calculator, in
addition to any others you have defined. Vulnerability calculators run every time a
vulnerable item record is created or updated, and can impact initial import
performance.
- During the initial import of records, certain notification-related business rules can
cause many notifications to be generated, impacting performance. Prior to your initial
import, disable the business rules.
- If you wish to use a different scanner than the Qualys default, see set up scanner
appliances.
- Have your Qualys server URL and authentication credentials ready. The credentials must
provide adequate permissions for retrieving knowledge, scan, and detection information for
a Qualys subscription.
- Version 10.3: If you plan to use host tags in Vulnerability Response Assignment or Vulnerability Group Rules, ensure the Qualys Host List integration was run prior to creating rules.