Qualys Attribute Reference
This reference lists the attributes that Device Security collects from Qualys,
their names as stored in Device Security, and the Device Security fields they map to.
When
Device Security integrates with Qualys, it enhances vulnerability
management for your devices. The attributes in this reference cover Qualys appliance
records, global asset view data, device details from vulnerability scans, and individual
vulnerability findings.
The third-party attribute name in Device Security refers to the attribute name
as it appears in the Assets Inventory table and in Query Engine. This follows the format
of third-party-name.attribute-name.
When viewing the attribute name in the Assets Inventory table column selector or on a
Device Details page, where the third-party name can be found as a header for the
attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the
Query Builder and in the Assets Inventory table, but under , the attribute would appear as macAddress.
Appliance List Attributes
Device Security collects appliance list attributes from Qualys. The following table lists each Qualys attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Qualys Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
INTERFACE_SETTINGS.DNS.DOMAIN | — | domain | Domain |
INTERFACE_SETTINGS.IP_ADDRESS | — | IP Address; id | IP ADDRESS |
ACTIVATION_CODE | qualys.scanner.activation_code | — | ACTIVATION CODE |
ASSET_GROUP_COUNT | qualys.scanner.asset_group_count | — | ASSET GROUP COUNT |
ASSET_GROUP_LIST | qualys.scanner.asset_group_list | — | ASSET GROUP LIST |
COMMENTS | qualys.scanner.comments | — | Comments |
HEARTBEATS_MISSED | qualys.scanner.heartbeats_missed | — | HEARTBEATS MISSED |
ID | qualys.scanner.id | — | Unique identifier |
LAST_UPDATED_DATE | qualys.scanner.last_updated_date | — | LAST UPDATED DATE |
MAX_CAPACITY_UNITS | qualys.scanner.max_capacity_units | — | MAX CAPACITY UNITS |
ML_LATEST | qualys.scanner.ml_latest | — | ML LATEST |
MODEL_NUMBER | qualys.scanner.model_number | — | MODEL NUMBER |
NAME | qualys.scanner.name | — | Name |
POLLING_INTERVAL | qualys.scanner.polling_interval | — | POLLING INTERVAL |
RUNNING_SCAN_COUNT | qualys.scanner.running_scan_count | — | RUNNING SCAN COUNT |
RUNNING_SLICES_COUNT | qualys.scanner.running_slices_count | — | RUNNING SLICES COUNT |
SERIAL_NUMBER | qualys.scanner.serial_number | — | SERIAL NUMBER |
SOFTWARE_VERSION | qualys.scanner.software_version | — | SOFTWARE VERSION |
SS_CONNECTION | qualys.scanner.ss_connection | — | SS CONNECTION |
SS_LAST_CONNECTED | qualys.scanner.ss_last_connected | — | SS LAST CONNECTED |
STATUS | qualys.scanner.status | — | Status |
TYPE | qualys.scanner.type | — | Type |
UPDATED | qualys.scanner.updated | — | Updated |
USER_LOGIN | qualys.scanner.user_login | — | USER LOGIN |
Global Asset View Assets Attributes
Device Security collects global asset view assets attributes from Qualys. The following table lists each Qualys attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Qualys Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
assetName | qualys.assetname | hostname | Asset name |
address | qualys.address | IP Address | Address |
hardware.model | qualys.hardware.model | Model | Model of the device |
operatingSystem | — | raw_os | Operating system |
biosSerialNumber | qualys.biosserialnumber | Serial Number | Bios serial number |
softwareListData | — | third_party_learned_installed_software | Software list data |
networkInterfaceListData | — | third_party_learned_network_interfaces | Network interface list data |
activity.lastScannedDate | qualys.activity.lastscanneddate | — | Last scanned date |
activity.source | qualys.activity.source | — | Source |
agent.activations | qualys.agent.activations | — | Activations |
agent.configurationProfile | qualys.agent.configurationprofile | — | Configuration profile |
agent.connectedFrom | qualys.agent.connectedfrom | — | Connected from |
agent.errorStatus | qualys.agent.errorstatus | — | Error status |
agent.lastActivity | qualys.agent.lastactivity | — | Last activity |
agent.lastCheckedIn | qualys.agent.lastcheckedin | — | Last checked in |
agent.lastInventory | qualys.agent.lastinventory | — | Last inventory |
agent.udcManifestAssigned | qualys.agent.udcmanifestassigned | — | Udc manifest assigned |
agent.version | qualys.agent.version | — | Version |
agentId | qualys.agentid | — | Agent ID |
assetId | qualys.assetid | — | Asset ID |
assetType | qualys.assettype | — | Asset type |
assetUUID | qualys.assetuuid | — | Asset UUID |
assignedLocation | qualys.assignedlocation | — | Assigned location |
biosAssetTag | qualys.biosassettag | — | Bios asset tag |
biosDescription | qualys.biosdescription | — | Bios description |
businessAppListData | qualys.businessapplistdata | — | Business app list data |
businessInformation | qualys.businessinformation | — | Business information |
cloudProvider | qualys.cloudprovider | — | Cloud provider |
container.hasSensor | qualys.container.hassensor | — | Has sensor |
container.noOfContainers | qualys.container.noofcontainers | — | No of containers |
container.noOfImages | qualys.container.noofimages | — | No of images |
container.product | qualys.container.product | — | Product |
container.version | qualys.container.version | — | Version |
cpuCount | qualys.cpucount | — | Number of CPUs |
createdDate | qualys.createddate | — | Created date |
criticality.default | qualys.criticality.default | — | Default |
criticality.isDefault | qualys.criticality.isdefault | — | Is default |
criticality.lastUpdated | qualys.criticality.lastupdated | — | Last updated |
criticality.score | qualys.criticality.score | — | Score |
customAttributes | qualys.customattributes | — | Custom attributes |
dnsName | qualys.dnsname | — | Dns name |
domain | qualys.domain | — | Domain |
domainRole | qualys.domainrole | — | Domain role |
easmTags | qualys.easmtags | — | Easm tags |
hardware.category | qualys.hardware.category | — | Category |
hardware.category1 | qualys.hardware.category1 | — | Category1 |
hardware.category2 | qualys.hardware.category2 | — | Category2 |
hardware.fullName | qualys.hardware.fullname | — | Full name |
hardware.lifecycle | qualys.hardware.lifecycle | — | Lifecycle |
hardware.manufacturer | qualys.hardware.manufacturer | — | Manufacturer of the device |
hardware.productFamily | qualys.hardware.productfamily | — | Product family |
hardware.productName | qualys.hardware.productname | — | Product name |
hardware.productUrl | qualys.hardware.producturl | — | Product URL |
hardware.taxonomy.category1 | qualys.hardware.taxonomy.category1 | — | Category1 |
hardware.taxonomy.category2 | qualys.hardware.taxonomy.category2 | — | Category2 |
hardware.taxonomy.id | qualys.hardware.taxonomy.id | — | Unique identifier |
hardware.taxonomy.name | qualys.hardware.taxonomy.name | — | Name of the device |
hostId | qualys.hostid | — | Host ID |
hostingCategory1 | qualys.hostingcategory1 | — | Hosting category1 |
hwUUID | qualys.hwuuid | — | Hw UUID |
inventory | qualys.inventory | — | Inventory |
inventory.created | qualys.inventory.created | — | Created |
inventory.lastUpdated | qualys.inventory.lastupdated | — | Last updated |
inventory.source | qualys.inventory.source | — | Source |
inventoryListData | qualys.inventorylistdata | — | Inventory list data |
isContainerHost | qualys.iscontainerhost | — | Is container host |
lastBoot | qualys.lastboot | — | Last boot |
lastLocation | qualys.lastlocation | — | Last location |
lastLoggedOnUser | qualys.lastloggedonuser | — | Last logged on user |
lastModifiedDate | qualys.lastmodifieddate | — | Last modified date |
lparId | qualys.lparid | — | Lpar ID |
missingSoftware | qualys.missingsoftware | — | Missing software |
netbiosName | qualys.netbiosname | — | Netbios name |
openPortListData | qualys.openportlistdata | — | Open port list data |
operatingSystem.architecture | qualys.operatingsystem.architecture | — | Architecture |
operatingSystem.category | qualys.operatingsystem.category | — | Category |
operatingSystem.category1 | qualys.operatingsystem.category1 | — | Category1 |
operatingSystem.category2 | qualys.operatingsystem.category2 | — | Category2 |
operatingSystem.cpe | qualys.operatingsystem.cpe | — | CPE |
operatingSystem.cpeId | qualys.operatingsystem.cpeid | — | Cpe ID |
operatingSystem.cpeType | qualys.operatingsystem.cpetype | — | CPE type |
operatingSystem.edition | qualys.operatingsystem.edition | — | Edition |
operatingSystem.fullName | qualys.operatingsystem.fullname | — | Full name |
operatingSystem.installDate | qualys.operatingsystem.installdate | — | Install date |
operatingSystem.lifecycle | qualys.operatingsystem.lifecycle | — | Lifecycle |
operatingSystem.marketVersion | qualys.operatingsystem.marketversion | — | Market version |
operatingSystem.osName | qualys.operatingsystem.osname | — | Os name |
operatingSystem.productFamily | qualys.operatingsystem.productfamily | — | Product family |
operatingSystem.productName | qualys.operatingsystem.productname | — | Product name |
operatingSystem.productUrl | qualys.operatingsystem.producturl | — | Product URL |
operatingSystem.publisher | qualys.operatingsystem.publisher | — | Publisher |
operatingSystem.release | qualys.operatingsystem.release | — | Release |
operatingSystem.taxonomy.category1 | qualys.operatingsystem.taxonomy.category1 | — | Category1 |
operatingSystem.taxonomy.category2 | qualys.operatingsystem.taxonomy.category2 | — | Category2 |
operatingSystem.taxonomy.id | qualys.operatingsystem.taxonomy.id | — | Unique identifier |
operatingSystem.taxonomy.name | qualys.operatingsystem.taxonomy.name | — | Name of the device |
operatingSystem.update | qualys.operatingsystem.update | — | Update |
operatingSystem.version | qualys.operatingsystem.version | — | Version |
organizationName | qualys.organizationname | — | Organization name |
passiveSensor | qualys.passivesensor | — | Passive sensor |
processor.coresPerSocket | qualys.processor.corespersocket | — | Cores per socket |
processor.description | qualys.processor.description | — | Description |
processor.multithreadingStatus | qualys.processor.multithreadingstatus | — | Multithreading status |
processor.noOfSocket | qualys.processor.noofsocket | — | No of socket |
processor.numCPUs | qualys.processor.numcpus | — | Num cp us |
processor.speed | qualys.processor.speed | — | Speed of the device connection |
processor.threadsPerCore | qualys.processor.threadspercore | — | Threads per core |
provider | qualys.provider | — | Provider |
riskScore | qualys.riskscore | — | Risk score |
sensor.activatedForModules | qualys.sensor.activatedformodules | — | Activated for modules |
sensor.firstEasmScanDate | qualys.sensor.firsteasmscandate | — | First easm scan date |
sensor.lastComplianceScan | qualys.sensor.lastcompliancescan | — | Last compliance scan |
sensor.lastEasmScanDate | qualys.sensor.lasteasmscandate | — | Last easm scan date |
sensor.lastFullScan | qualys.sensor.lastfullscan | — | Last full scan |
sensor.lastPcScanDateAgent | qualys.sensor.lastpcscandateagent | — | Last pc scan date agent |
sensor.lastPcScanDateScanner | qualys.sensor.lastpcscandatescanner | — | Last pc scan date scanner |
sensor.lastVMScan | qualys.sensor.lastvmscan | — | Last vm scan |
sensor.lastVmScanDateAgent | qualys.sensor.lastvmscandateagent | — | Last vm scan date agent |
sensor.lastVmScanDateScanner | qualys.sensor.lastvmscandatescanner | — | Last vm scan date scanner |
sensor.pendingActivationForModules | qualys.sensor.pendingactivationformodules | — | Pending activation for modules |
sensorLastUpdatedDate | qualys.sensorlastupdateddate | — | Sensor last updated date |
serviceList.service | qualys.servicelist.service | — | Service |
softwareComponent | qualys.softwarecomponent | — | Software component |
subdomain | qualys.subdomain | — | Subdomain |
tagList.tag | qualys.taglist.tag | — | Tag |
timeZone | qualys.timezone | — | Time zone |
totalMemory | qualys.totalmemory | — | Total memory |
userAccountListData | qualys.useraccountlistdata | — | User account list data |
volumeListData | qualys.volumelistdata | — | Volume list data |
Device Vulnerability Attributes
Device Security collects device vulnerability attributes from Qualys. The following table lists each Qualys attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Qualys Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
DNS_DATA.HOSTNAME | qualys.dns_data.hostname | hostname | Hostname |
device_id | — | id; MAC Address | Device ID |
CLOUD_PROVIDER | qualys.cloud_provider | — | Cloud provider |
CLOUD_RESOURCE_ID | qualys.cloud_resource_id | — | Cloud resource ID |
CLOUD_SERVICE | qualys.cloud_service | — | Cloud service |
DNS_DATA.DOMAIN | qualys.dns_data.domain | — | Domain |
DNS_DATA.FQDN | qualys.dns_data.fqdn | — | Fqdn |
EC2_INSTANCE_ID | qualys.ec2_instance_id | — | Ec2 instance ID |
QG_HOSTID | qualys.hostid | — | Qg hostid |
ID | qualys.id | — | Unique identifier |
LAST_VM_AUTH_SCANNED_DATE | qualys.last_vm_auth_scanned_date | — | Last vm auth scanned date |
LAST_VM_AUTH_SCANNED_DURATION | qualys.last_vm_auth_scanned_duration | — | Last vm auth scanned duration |
METADATA.EC2.ATTRIBUTE.LAST_ERROR | qualys.metadata.ec2.attribute.last_error | — | Last error |
METADATA.EC2.ATTRIBUTE.LAST_ERROR_DATE | qualys.metadata.ec2.attribute.last_error_date | — | Last error date |
METADATA.EC2.ATTRIBUTE.LAST_STATUS | qualys.metadata.ec2.attribute.last_status | — | Last status |
METADATA.EC2.ATTRIBUTE.LAST_SUCCESS_DATE | qualys.metadata.ec2.attribute.last_success_date | — | Last success date |
METADATA.EC2.ATTRIBUTE.NAME | qualys.metadata.ec2.attribute.name | — | Name |
METADATA.EC2.ATTRIBUTE.VALUE | qualys.metadata.ec2.attribute.value | — | Value |
NETBIOS | qualys.netbios | — | Netbios |
Vulnerability Attributes
Device Security collects vulnerability attributes from Qualys. The following table lists each Qualys attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Qualys Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
LAST_FOUND_DATETIME | qualys.last_found_datetime | detected_time | Last found datetime |
SEVERITY | — | risk_level | Severity |
severity | qualys.severity | severity | Severity |
CLOUD_PROVIDER | qualys.cloud_provider | — | Cloud provider |
CLOUD_RESOURCE_ID | qualys.cloud_resource_id | — | Cloud resource ID |
CLOUD_SERVICE | qualys.cloud_service | — | Cloud service |
deviceid | qualys.deviceid | — | Device ID |
DNS_DATA.DOMAIN | qualys.dns_data.domain | — | Domain |
DNS_DATA.FQDN | qualys.dns_data.fqdn | — | Fqdn |
DNS_DATA.HOSTNAME | qualys.dns_data.hostname | — | Hostname |
EC2_INSTANCE_ID | qualys.ec2_instance_id | — | Ec2 instance ID |
FIRST_FOUND_DATETIME | qualys.first_found_datetime | — | First found datetime |
IS_DISABLED | qualys.is_disabled | — | Is disabled |
IS_IGNORED | qualys.is_ignored | — | Is ignored |
LAST_PROCESSED_DATETIME | qualys.last_processed_datetime | — | Last processed datetime |
LAST_SCAN_DATETIME | qualys.last_scan_datetime | — | Last scan datetime |
LAST_TEST_DATETIME | qualys.last_test_datetime | — | Last test datetime |
LAST_UPDATE_DATETIME | qualys.last_update_datetime | — | Last update datetime |
LAST_VM_AUTH_SCANNED_DATE | qualys.last_vm_auth_scanned_date | — | Last vm auth scanned date |
LAST_VM_AUTH_SCANNED_DURATION | qualys.last_vm_auth_scanned_duration | — | Last vm auth scanned duration |
LAST_VM_SCANNED_DATE | qualys.last_vm_scanned_date | — | Last vm scanned date |
LAST_VM_SCANNED_DURATION | qualys.last_vm_scanned_duration | — | Last vm scanned duration |
METADATA.EC2.ATTRIBUTE.LAST_ERROR | qualys.metadata.ec2.attribute.last_error | — | Last error |
METADATA.EC2.ATTRIBUTE.LAST_ERROR_DATE | qualys.metadata.ec2.attribute.last_error_date | — | Last error date |
METADATA.EC2.ATTRIBUTE.LAST_STATUS | qualys.metadata.ec2.attribute.last_status | — | Last status |
METADATA.EC2.ATTRIBUTE.LAST_SUCCESS_DATE | qualys.metadata.ec2.attribute.last_success_date | — | Last success date |
METADATA.EC2.ATTRIBUTE.NAME | qualys.metadata.ec2.attribute.name | — | Name |
METADATA.EC2.ATTRIBUTE.VALUE | qualys.metadata.ec2.attribute.value | — | Value |
NETBIOS | qualys.netbios | — | Netbios |
QG_HOSTID | qualys.qg_hostid | — | Qg hostid |
RESULTS | qualys.results | — | Results |
STATUS | qualys.status | — | Status |
TIMES_FOUND | qualys.times_found | — | Times found |
TRACKING_METHOD | qualys.tracking_method | — | Tracking method |
UNIQUE_VULN_ID | qualys.unique_vuln_id | — | Unique vuln ID |
* Only some attributes map to a Device Security Common Attribute.