{
  "name": "qualys_was",
  "title": "Qualys Web Application Scanning (WAS)",
  "version": "0.6.0",
  "release": "beta",
  "description": "Collect data from Qualys Web Application Scanning platform with Elastic Agent or Agentless",
  "type": "integration",
  "download": "/epr/qualys_was/qualys_was-0.6.0.zip",
  "path": "/package/qualys_was/0.6.0",
  "conditions": {
    "kibana": {
      "version": "^8.18.0 || ^9.0.0"
    },
    "elastic": {
      "subscription": "basic"
    }
  },
  "owner": {
    "type": "elastic",
    "github": "elastic/security-service-integrations"
  },
  "categories": [
    "security",
    "vulnerability_management"
  ],
  "signature_path": "/epr/qualys_was/qualys_was-0.6.0.zip.sig",
  "format_version": "3.4.0",
  "readme": "/package/qualys_was/0.6.0/docs/README.md",
  "license": "basic",
  "screenshots": [
    {
      "src": "/img/qualys-was-detections-dashboard.png",
      "path": "/package/qualys_was/0.6.0/img/qualys-was-detections-dashboard.png",
      "title": "Qualys WAS Detection Dashboard Screenshot",
      "size": "600x600",
      "type": "image/png"
    }
  ],
  "assets": [
    "/package/qualys_was/0.6.0/LICENSE.txt",
    "/package/qualys_was/0.6.0/changelog.yml",
    "/package/qualys_was/0.6.0/manifest.yml",
    "/package/qualys_was/0.6.0/validation.yml",
    "/package/qualys_was/0.6.0/docs/README.md",
    "/package/qualys_was/0.6.0/img/qualys-was-detections-dashboard.png",
    "/package/qualys_was/0.6.0/img/qualys-was-logo.svg",
    "/package/qualys_was/0.6.0/kibana/tags.yml",
    "/package/qualys_was/0.6.0/data_stream/vulnerability/manifest.yml",
    "/package/qualys_was/0.6.0/data_stream/vulnerability/sample_event.json",
    "/package/qualys_was/0.6.0/kibana/dashboard/qualys_was-e98bb088-8853-4e6a-8887-c3f301100fe6.json",
    "/package/qualys_was/0.6.0/data_stream/vulnerability/fields/base-fields.yml",
    "/package/qualys_was/0.6.0/data_stream/vulnerability/fields/beats.yml",
    "/package/qualys_was/0.6.0/data_stream/vulnerability/fields/fields.yml",
    "/package/qualys_was/0.6.0/data_stream/vulnerability/fields/kb_fields.yml",
    "/package/qualys_was/0.6.0/data_stream/vulnerability/agent/stream/cel.yml.hbs",
    "/package/qualys_was/0.6.0/data_stream/vulnerability/elasticsearch/ingest_pipeline/default.yml",
    "/package/qualys_was/0.6.0/data_stream/vulnerability/elasticsearch/ingest_pipeline/pipeline_knowledge_base.yml"
  ],
  "policy_templates": [
    {
      "name": "qualys_was",
      "title": "Qualys WAS data",
      "description": "Collect Qualys WAS data.",
      "inputs": [
        {
          "type": "cel",
          "vars": [
            {
              "name": "username",
              "type": "text",
              "title": "Username",
              "description": "Username for the Qualys WAS.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "password",
              "type": "password",
              "title": "Password",
              "description": "Password for the Qualys WAS.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http[s]://<user>:<password>@<server name/ip>:<port>. Please ensure your username and password are in URL encoded format.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/fleet/current/elastic-agent-ssl-configuration.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "#certificate_authorities:\n#  - |\n#    -----BEGIN CERTIFICATE-----\n#    MIIDCjCCAfKgAwIBAgITJ706Mu2wJlKckpIvkWxEHvEyijANBgkqhkiG9w0BAQsF\n#    ADAUMRIwEAYDVQQDDAlsb2NhbGhvc3QwIBcNMTkwNzIyMTkyOTA0WhgPMjExOTA2\n#    MjgxOTI5MDRaMBQxEjAQBgNVBAMMCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcNAQEB\n#    BQADggEPADCCAQoCggEBANce58Y/JykI58iyOXpxGfw0/gMvF0hUQAcUrSMxEO6n\n#    fZRA49b4OV4SwWmA3395uL2eB2NB8y8qdQ9muXUdPBWE4l9rMZ6gmfu90N5B5uEl\n#    94NcfBfYOKi1fJQ9i7WKhTjlRkMCgBkWPkUokvBZFRt8RtF7zI77BSEorHGQCk9t\n#    /D7BS0GJyfVEhftbWcFEAG3VRcoMhF7kUzYwp+qESoriFRYLeDWv68ZOvG7eoWnP\n#    PsvZStEVEimjvK5NSESEQa9xWyJOmlOKXhkdymtcUd/nXnx6UTCFgnkgzSdTWV41\n#    CI6B6aJ9svCTI2QuoIq2HxX/ix7OvW1huVmcyHVxyUECAwEAAaNTMFEwHQYDVR0O\n#    BBYEFPwN1OceFGm9v6ux8G+DZ3TUDYxqMB8GA1UdIwQYMBaAFPwN1OceFGm9v6ux\n#    8G+DZ3TUDYxqMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAG5D\n#    874A4YI7YUwOVsVAdbWtgp1d0zKcPRR+r2OdSbTAV5/gcS3jgBJ3i1BN34JuDVFw\n#    3DeJSYT3nxy2Y56lLnxDeF8CUTUtVQx3CuGkRg1ouGAHpO/6OqOhwLLorEmxi7tA\n#    H2O8mtT0poX5AnOAhzVy7QW0D/k4WaoLyckM5hUa6RtvgvLxOwA0U+VGurCDoctu\n#    8F4QOgTAWyh8EZIwaKCliFRSynDpv3JTUwtfZkxo6K6nce1RhCWFAsMvDZL8Dgc0\n#    yvgJ38BRsFOtkRuAGSf6ZUwTO8JJRRIFnpUzXflAnGivK9M13D5GEQMmIl6U9Pvk\n#    sxSmbIUfc2SGJGCJD4I=\n#    -----END CERTIFICATE-----\n"
            }
          ],
          "title": "Collect Qualys WAS data via API",
          "description": "Collecting Qualys WAS via API."
        }
      ],
      "multiple": true,
      "deployment_modes": {
        "default": {
          "enabled": true
        },
        "agentless": {
          "enabled": true,
          "release": "ga"
        }
      }
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "qualys_was.vulnerability",
      "title": "Collects Web Application Vulnerabilty Findings from Qualys WAS platform.",
      "release": "beta",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "qualys_was_vulnerability"
              ]
            },
            {
              "name": "url",
              "type": "text",
              "title": "URL",
              "description": "Complete base URL of the Qualys Server API. Include the protocol",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "initial_interval",
              "type": "text",
              "title": "Initial Interval",
              "description": "Determines the initial minimum time for the last time a vulnerability was tested for. The first run of integration when enabled will query for all vulnerabilities from (now - Initial Interval) to now. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "24h"
            },
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Interval between querying for latest vulnerability results. Consider the web application scanning schedule when setting this value. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "24h"
            },
            {
              "name": "disable_information_gathered",
              "type": "bool",
              "title": "Disable Information Gathered",
              "description": "When enabled, will not include findings that are of type \"information gathered\"",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "disable_sensitive_content",
              "type": "bool",
              "title": "Disable Sensitive Content",
              "description": "When enabled, will not include findings that are of type \"sensitive content\"",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "disable_verbose",
              "type": "bool",
              "title": "Disable Verbose Result",
              "description": "Default is true which retrieves the tags on web application data and results of scans. Verbose mode effects performance of the queries and the size of responses. Using a large batch size with verbose enabled could result in time out failures or non 200 responses from the Qualys endpoint. Verbose mode responses include a history of all scans ever made that tested for this vulnerability. we do not ingest or index this data. Consider a maintenance schedule of removing old scans to reduce the response size when verbose is enabled.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "batch_size",
              "type": "integer",
              "title": "Batch Size",
              "description": "Batch size for the response of the Qualys Server API. This parameter specifies the truncation limit for the response. Specify 0 for default limit for the API calls.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 50
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Supported time units are ns, us, ms, s, m, h. Requests may take significant time, so short timeouts are not recommended. When verbose mode is enabled, requests will take longer and require a longer connection timeout.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "10m"
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the data is parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs HTTP requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_resource_tracer_filename) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Web Application Scanning Vulnerability Findings",
          "description": "Collect Web Application Scanning Vulnerability Finding data from Qualys WAS platform.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "qualys_was",
      "path": "vulnerability"
    }
  ]
}
