Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Components installed with the Qualys Vulnerability Integration

The following roles, integration jobs, and tables are installed with the Qualys Vulnerability Integration.

Note: The Application Files table lists the components that are installed with this application. For instructions on how to access this table, see Find components installed with an application.

View filtered lists for components installed with an application

Filter the Applications Files table so that only the roles, scheduled jobs, and tables that are installed with an application are displayed. The application you want to view these components for should be installed so that its files are loaded onto the instance and into the metadata table. Follow these steps to view filtered lists from the Applications Files table.

  1. In the filter navigator, enter sys_metadata.list to navigate to the metadata table.
  2. Select the condition builder (filter icon), and select, Application > is followed by the name of your application. For example, Application > is > Vulnerability Response.
  3. In the condition builder, to add a second filter, select AND, then select, Class > is a and choose one of the following classes from the list: Role, Scheduled job, or Table.
  4. Select Run.

The results for the class you selected are displayed in a filtered list.

Roles installed

Role title \[name\]DescriptionContains roles
sn\_vul\_qualys.readHas read access to the Qualys Vulnerability Integration records. 
sn\_vul\_qualys.userUser for Qualys Vulnerability Integration. Can read and write recordssn\_vul\_qualys.read
sn\_vul\_qualys.adminAdministrator forQualys Vulnerability Integration. For example, you can modify integration start dates and perform some advanced configuration settings.- sn\_vul\_qualys.user - sn\_vul.vulnerability\_analyst
sn\_vul.configure\_qualys\_integrationCan configure the Qualys Vulnerability Integrationsn\_vul\_qualys.admin

Integration jobs installed

Integration jobDescription
Qualys Static Search List IntegrationSynchronizes Qualys search lists for finding vulnerable entries. Retrieves only static list type records.
Qualys Comprehensive Host Detection Integration

Retrieves host and vulnerability data from Qualys and processes it in your instance.

It coordinates the REST message calls to the Host Detection API.

The output of this integration is vulnerable items. This integration imports all the states of the vulnerability: New,Fixed, Active, and Reopened. By default, this integration is inactive and runs weekly.

Note: After this integration is activated, the daily comprehensive job imports only the New, Fixed, and Reopened states.

Qualys Host List IntegrationRetrieves authenticated and unauthenticated host scan data and host tags from Qualys once a week and stores it in the Discovered Items module in your instance. Helps identify assets that haven't been scanned recently.
Qualys Host Detection IntegrationRetrieves host and vulnerability data from Qualys and processes it in your instance. It coordinates the REST message calls to the Host List Detection API.The outputs of this integration are vulnerable items. Qualys host tags are imported in this integration.
Qualys Ticket IntegrationRetrieves Qualys tickets and adds them to your instance. It coordinates the REST message calls to the ticket list API.There are often fewer tickets than Host Detections since Qualys settings can constrain the detections that result in a ticket.
Qualys Option Profile List IntegrationRetrieves option profiles from the Qualys product. Option profiles include scan settings which are required when you initiate scans from your ServiceNow AI Platform instance.
Qualys Appliance List IntegrationRetrieves scanner appliance information from Qualys.
Qualys Asset Group IntegrationRetrieves asset group information from Qualys. Asset groups are used to identify which scanner appliances to use for scanning matching configuration items.
Qualys Knowledge Base \(Backfill\)Retrieves Qualys knowledge base entries.Scheduled to run after the Qualys Knowledge Base Integration. Updates your instance with any QIDs that were referenced in the Qualys Knowledge Base or Qualys Host Detection integration but did not exist in the system.
Qualys Knowledge BaseRetrieves Qualys knowledge base entries. The retrieved data is based on the date the vulnerabilities were updated by Qualys and since the last time the integration ran.This data is useful for populating historical data into your instance as well as ensuring the Qualys Identifiers \(QIDs\) are up to date.
Qualys Dynamic Search List IntegrationSynchronizes Qualys search lists for finding vulnerable entries, and retrieves dynamic list type records.
Fixing the detections for updated key for QualysA hashed combination of fields that provided a way to identify and tie a detection to a Qualys vulnerable item.
Qualys Update existing discovered items with network partition identifierUpdates your existing discovered items. CIs for your existing Qualys Vulnerability Integration data are created or updated to include the network partition identifier granularity.

Tables installed

TableDescription
Search List Vulnerabilitysn\_vul\_qualys\_m2m\_search\_list\_vulStores the mapping between the Qualys search list and a vulnerability.
Qualys Vulnerability Scannersn\_vul\_qualys\_scannerTable that extends Vulnerability Scanners to store scanner information for the Qualys rescan feature.
Qualys Search Listssn\_vul\_qualys\_search\_listStores search lists retrieved by the Qualys search list integration.
Qualys Appliance Importsn\_vul\_qualys\_appliance\_impTable extending the import set row. Field map transformation is skipped and the response attachment is processed directly with the onComplete script.
Qualys CIsn\_vul\_qualys\_ciTable no longer used.
Host Detection Paginationsn\_vul\_qualys\_host\_detection\_paginationTable no longer used.
Qualys Integration Runsn\_vul\_qualys\_integration\_runTable no longer used.
Qualys Integrationsn\_vul\_qualys\_integrationTable extending the vulnerability integration and stores all the integrations that correspond to Qualys.
Qualys Static Search List Importsn\_vul\_qualys\_static\_search\_list\_impTable extending the import set row. Field maps are used to transform data to the target table, Qualys Search Lists.
Qualys Knowledge Basesn\_vul\_qualys\_knowledge\_baseTable extending the import set row. Field map transformation is skipped and the response attachment is processed directly with the onComplete script.
Qualys Ticket Listsn\_vul\_qualys\_ticket\_list\_impTable extending the import set row. Field map transformation is skipped and the response attachment is processed directly with the onComplete script.
Qualys Option Profilesn\_vul\_qualys\_option\_profileTable storing the option profiles retrived from Qualys. This table used with the rescan.
Qualys Dynamic Search List Importsn\_vul\_qualys\_dynamic\_search\_list\_impTable extending the import set row. Field maps are used to transform data to the target table, Qualys Search Lists.
Qualys Import Set Re-Runsn\_vul\_qualys\_import\_rerunTable no longer used.
Qualys Option Profile Importsn\_vul\_qualys\_option\_profile\_importTable extending the import set row. Field map transformation is skipped and the response attachment is processed directly with the onComplete script.