{
  "name": "qualys_gav",
  "title": "Qualys Global AssetView",
  "version": "0.10.0",
  "release": "beta",
  "description": "Collect logs from Qualys Global AssetView with Elastic Agent.",
  "type": "integration",
  "download": "/epr/qualys_gav/qualys_gav-0.10.0.zip",
  "path": "/package/qualys_gav/0.10.0",
  "icons": [
    {
      "src": "/img/qualys_gav-logo.svg",
      "path": "/package/qualys_gav/0.10.0/img/qualys_gav-logo.svg",
      "title": "Qualys Global AssetView logo",
      "size": "32x32",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.19.11 || ^9.2.5"
    },
    "elastic": {
      "subscription": "basic"
    }
  },
  "owner": {
    "type": "elastic",
    "github": "elastic/security-service-integrations"
  },
  "categories": [
    "security"
  ],
  "signature_path": "/epr/qualys_gav/qualys_gav-0.10.0.zip.sig",
  "format_version": "3.4.0",
  "readme": "/package/qualys_gav/0.10.0/docs/README.md",
  "license": "basic",
  "screenshots": [
    {
      "src": "/img/qualys_gav-asset.png",
      "path": "/package/qualys_gav/0.10.0/img/qualys_gav-asset.png",
      "title": "Asset Dashboard",
      "size": "600x600",
      "type": "image/png"
    }
  ],
  "assets": [
    "/package/qualys_gav/0.10.0/LICENSE.txt",
    "/package/qualys_gav/0.10.0/changelog.yml",
    "/package/qualys_gav/0.10.0/manifest.yml",
    "/package/qualys_gav/0.10.0/docs/README.md",
    "/package/qualys_gav/0.10.0/img/qualys_gav-asset.png",
    "/package/qualys_gav/0.10.0/img/qualys_gav-logo.svg",
    "/package/qualys_gav/0.10.0/data_stream/asset/lifecycle.yml",
    "/package/qualys_gav/0.10.0/data_stream/asset/manifest.yml",
    "/package/qualys_gav/0.10.0/data_stream/asset/sample_event.json",
    "/package/qualys_gav/0.10.0/kibana/dashboard/qualys_gav-e7e0529f-6cb1-4b01-b5f8-568cfb07c306.json",
    "/package/qualys_gav/0.10.0/data_stream/asset/fields/base-fields.yml",
    "/package/qualys_gav/0.10.0/data_stream/asset/fields/beats.yml",
    "/package/qualys_gav/0.10.0/data_stream/asset/fields/fields.yml",
    "/package/qualys_gav/0.10.0/data_stream/asset/fields/is-transform-source-true.yml",
    "/package/qualys_gav/0.10.0/elasticsearch/transform/latest_asset/manifest.yml",
    "/package/qualys_gav/0.10.0/elasticsearch/transform/latest_asset/transform.yml",
    "/package/qualys_gav/0.10.0/data_stream/asset/agent/stream/cel.yml.hbs",
    "/package/qualys_gav/0.10.0/data_stream/asset/elasticsearch/ilm/default_policy.json",
    "/package/qualys_gav/0.10.0/data_stream/asset/elasticsearch/ingest_pipeline/default.yml",
    "/package/qualys_gav/0.10.0/elasticsearch/transform/latest_asset/fields/base-fields.yml",
    "/package/qualys_gav/0.10.0/elasticsearch/transform/latest_asset/fields/beats.yml",
    "/package/qualys_gav/0.10.0/elasticsearch/transform/latest_asset/fields/ecs.yml",
    "/package/qualys_gav/0.10.0/elasticsearch/transform/latest_asset/fields/fields.yml",
    "/package/qualys_gav/0.10.0/elasticsearch/transform/latest_asset/fields/is-transform-source-false.yml"
  ],
  "policy_templates": [
    {
      "name": "qualys_gav",
      "title": "Qualys Global AssetView",
      "description": "Collect logs from Qualys Global AssetView.",
      "inputs": [
        {
          "type": "cel",
          "vars": [
            {
              "name": "url",
              "type": "text",
              "title": "URL",
              "description": "Base URL of the Qualys Global AssetView API.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "username",
              "type": "text",
              "title": "Username",
              "description": "Username of the Qualys Global AssetView API.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "password",
              "type": "password",
              "title": "Password",
              "description": "Password to authenticate the Qualys Global AssetView API.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http[s]://<user>:<password>@<server name/ip>:<port>. Please ensure your username and password are in URL encoded format.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "#certificate_authorities:\n#  - |\n#    -----BEGIN CERTIFICATE-----\n#    MIIDCjCCAfKgAwIBAgITJ706Mu2wJlKckpIvkWxEHvEyijANBgkqhkiG9w0BAQsF\n#    ADAUMRIwEAYDVQQDDAlsb2NhbGhvc3QwIBcNMTkwNzIyMTkyOTA0WhgPMjExOTA2\n#    MjgxOTI5MDRaMBQxEjAQBgNVBAMMCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcNAQEB\n#    BQADggEPADCCAQoCggEBANce58Y/JykI58iyOXpxGfw0/gMvF0hUQAcUrSMxEO6n\n#    fZRA49b4OV4SwWmA3395uL2eB2NB8y8qdQ9muXUdPBWE4l9rMZ6gmfu90N5B5uEl\n#    94NcfBfYOKi1fJQ9i7WKhTjlRkMCgBkWPkUokvBZFRt8RtF7zI77BSEorHGQCk9t\n#    /D7BS0GJyfVEhftbWcFEAG3VRcoMhF7kUzYwp+qESoriFRYLeDWv68ZOvG7eoWnP\n#    PsvZStEVEimjvK5NSESEQa9xWyJOmlOKXhkdymtcUd/nXnx6UTCFgnkgzSdTWV41\n#    CI6B6aJ9svCTI2QuoIq2HxX/ix7OvW1huVmcyHVxyUECAwEAAaNTMFEwHQYDVR0O\n#    BBYEFPwN1OceFGm9v6ux8G+DZ3TUDYxqMB8GA1UdIwQYMBaAFPwN1OceFGm9v6ux\n#    8G+DZ3TUDYxqMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAG5D\n#    874A4YI7YUwOVsVAdbWtgp1d0zKcPRR+r2OdSbTAV5/gcS3jgBJ3i1BN34JuDVFw\n#    3DeJSYT3nxy2Y56lLnxDeF8CUTUtVQx3CuGkRg1ouGAHpO/6OqOhwLLorEmxi7tA\n#    H2O8mtT0poX5AnOAhzVy7QW0D/k4WaoLyckM5hUa6RtvgvLxOwA0U+VGurCDoctu\n#    8F4QOgTAWyh8EZIwaKCliFRSynDpv3JTUwtfZkxo6K6nce1RhCWFAsMvDZL8Dgc0\n#    yvgJ38BRsFOtkRuAGSf6ZUwTO8JJRRIFnpUzXflAnGivK9M13D5GEQMmIl6U9Pvk\n#    sxSmbIUfc2SGJGCJD4I=\n#    -----END CERTIFICATE-----\n"
            }
          ],
          "title": "Collect logs from Qualys Global AssetView API",
          "description": "Collecting logs via Qualys Global AssetView API."
        }
      ],
      "multiple": true,
      "deployment_modes": {
        "default": {
          "enabled": true
        },
        "agentless": {
          "enabled": true,
          "release": "ga"
        }
      }
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "qualys_gav.asset",
      "ilm_policy": "logs-qualys_gav.asset-default_policy",
      "title": "Collect Assets from Qualys Global AssetView.",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Duration between requests to the Qualys Global AssetView API. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "1h"
            },
            {
              "name": "batch_size",
              "type": "integer",
              "title": "Batch Size",
              "description": "Page size for the response of the Qualys Global AssetView API. Maximum allowed value is 100.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 100
            },
            {
              "name": "exclude_fields",
              "type": "text",
              "title": "Exclude Fields",
              "description": "Comma-separated list of fields to exclude from the asset object in the response. See [documentation](https://docs.qualys.com/en/csam/api/asset_host_data/get_host_details_of_all_assets.htm) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "include_fields",
              "type": "text",
              "title": "Include Fields",
              "description": "Comma-separated list of fields to be included in the asset object in the response. See [documentation](https://docs.qualys.com/en/csam/api/asset_host_data/get_host_details_of_all_assets.htm) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "max_executions",
              "type": "integer",
              "title": "Maximum Pages Per Interval",
              "description": "Maximum Pages Per Interval is the maximum number of pages that can be collected at each interval.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": 1000
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. Disabling the request tracer will delete any stored traces. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_enable) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field event.original.",
              "multi": false,
              "required": false,
              "show_user": true,
              "default": false
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "description": "Tags for the data-stream.",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "qualys_gav-asset"
              ]
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Supported time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "cloud_data",
              "type": "select",
              "title": "Cloud Metadata Source",
              "description": "What source to use to populate `cloud.*` fields.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "both"
            },
            {
              "name": "preserve_duplicate_custom_fields",
              "type": "bool",
              "title": "Preserve duplicate custom fields",
              "description": "Preserve qualys_gav.asset fields that were copied to Elastic Common Schema (ECS) fields.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "hide_sensitive",
              "type": "bool",
              "title": "Hide Sensitive Details",
              "description": "Hide sensitive user details such as phone number, street address etc.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": true
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Qualys Global AssetView Assets",
          "description": "Collect Qualys Global AssetView Assets.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "qualys_gav",
      "path": "asset"
    }
  ]
}
