# Qualys API integration into Elasticsearch

**URL:** <https://discuss.elastic.co/t/qualys-api-integration-into-elasticsearch/219888>\
**Category:** Elasticsearch\
**Created:** [February 19, 2020, 3:14am UTC](https://discuss.elastic.co/t/qualys-api-integration-into-elasticsearch/219888 "2020-02-19T03:14:30Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tanner8302](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tanner8302/32/94038_2.png) [@tanner8302](https://discuss.elastic.co/u/tanner8302)\
**Post date:** [February 19, 2020, 3:14am UTC](https://discuss.elastic.co/t/qualys-api-integration-into-elasticsearch/219888/1 "2020-02-19T03:14:30Z")

</div>

I am a current customer of Qualys and would like to create a reoccuring API call to Qualys from my Elasticsearch instance.

I am unclear on where I create and schedule cURL command to access this data. When I try and use them in the Dev tools console they do not appear to work?

Using 7.6 on Elasticsearch, APM, Kibana.

Thoughts?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 19, 2020, 2:26pm UTC](https://discuss.elastic.co/t/qualys-api-integration-into-elasticsearch/219888/2 "2020-02-19T14:26:03Z")

</div>

Hey,

maybe you can expand a little bit, what you try to do, as something that sounds simple usually has some drawbacks attached. Do you want to query some API endpoint and index that data into elasticsearch? Is this a single page of data or something you paginate through? What happens in case of a failure?

If you want to alert on data from the API endpoint, you could take a look at [Alerting](https://www.elastic.co/guide/en/elasticsearch/reference/current/xpack-alerting.html)

hope this helps as a start.

---

<div class="post-metadata">

**Author:** ![tanner8302](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tanner8302/32/94038_2.png) [@tanner8302](https://discuss.elastic.co/u/tanner8302)\
**Post date:** [February 19, 2020, 5:22pm UTC](https://discuss.elastic.co/t/qualys-api-integration-into-elasticsearch/219888/3 "2020-02-19T17:22:32Z")

</div>

Good Morning and thank you for your reply. I am trying to take the vulnerability assessment data out of Qualys using their rest API and get that into Elasticsearch. I can envision two ways to do this...1. I think the best method is to find some internal process within Elasticsearch to make a periodic call to Qualys using its API to get that vulnerability data OR 2. I could envision a JSON or XML file being created by Qualys that I could pick up with Filebeat to send to Elasticsearch.

Thanks again, looking forward to your thoughts....

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 20, 2020, 7:44am UTC](https://discuss.elastic.co/t/qualys-api-integration-into-elasticsearch/219888/4 "2020-02-20T07:44:08Z")

</div>

that's tricky to tell without knowing the qualys API. If that API requires some work (several requests) in order to gather all the data, then probably a small custom script might be a better idea, as you have full control over the execution. If it spits out a big XML/JSON blurb filebeat sounds like a good idea, as the data is easier to modify than within alerting.

From what I read, I think I would go with a script to have the full power of transformation, but that is just an outside hunch here as I don't understand the API well enough.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 19, 2020, 7:44am UTC](https://discuss.elastic.co/t/qualys-api-integration-into-elasticsearch/219888/5 "2020-03-19T07:44:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
