# Qualys VMDR bug

**URL:** <https://discuss.elastic.co/t/qualys-vmdr-bug/362777>\
**Category:** Elastic Agent\
**Tags:** integrations\
**Created:** [July 9, 2024, 8:34am UTC](https://discuss.elastic.co/t/qualys-vmdr-bug/362777 "2024-07-09T08:34:14Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![djkprojects](https://avatars.discourse-cdn.com/v4/letter/d/d2c977/32.png) [@djkprojects](https://discuss.elastic.co/u/djkprojects)\
**Post date:** [July 9, 2024, 8:34am UTC](https://discuss.elastic.co/t/qualys-vmdr-bug/362777/1 "2024-07-09T08:34:14Z")

</div>

Hello,

It looks that the v4.0.0 of Qualys VMDR integration is broken as when enabling Host Detection we are getting the following error:

> failed to check program: failed compilation: ERROR: :15:9: unsupported syntax '?'  
> | ?"xml": state.keep\_xml ? optional.of(string(xml)) : optional.none(),  
> | ........^ accessing config

Is the "?" in this line:

> <https://github.com/elastic/integrations/blob/91a6707d8e3af8854418a711f8f36fb2861a94be/packages/qualys_vmdr/data_stream/asset_host_detection/agent/stream/input.yml.hbs#L42>

necessary?

---

<div class="post-metadata">

**Author:** ![kcreddy](https://avatars.discourse-cdn.com/v4/letter/k/6f9a4e/32.png) [@kcreddy](https://discuss.elastic.co/u/kcreddy)\
**Post date:** [July 9, 2024, 9:16am UTC](https://discuss.elastic.co/t/qualys-vmdr-bug/362777/2 "2024-07-09T09:16:47Z")

</div>

Hey @djkprojects

> Is the "?" in this line necessary:

Yes, it defines an [optional type in CEL](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#max_executions-cel:~:text=The%20CEL%20environment%20enables%20the%20optional%20types%20library%20using%20the%20version%20defined%20here.), an underlying filebeat input used to ingest the data.

> It looks that the v4.0.0 of Qualys VMDR integration is broken as when enabling Host Detection we are getting the following error:

Did this error occur when you were upgrading from a previous version of the integration? If so, what was the previous version of the integration?

The optional type is also introduced in `v8.12.0` Elastic Stack. Can you also confirm the version of Elastic Agent you currently setup for the integration?

Elastic Agent version can be found by navigating to `Management -> Fleet -> Agents` and check `Version`.

---

<div class="post-metadata">

**Author:** ![djkprojects](https://avatars.discourse-cdn.com/v4/letter/d/d2c977/32.png) [@djkprojects](https://discuss.elastic.co/u/djkprojects)\
**Post date:** [July 17, 2024, 1:28pm UTC](https://discuss.elastic.co/t/qualys-vmdr-bug/362777/3 "2024-07-17T13:28:25Z")

</div>

Hello @kcreddy

We upgraded the agent to 8.13.4 and the integration works only partially.

for Host detection we get logs but sometimes it fails with error.message:

```auto
[
  failed eval: ERROR: <input>:12:19: no such key: HOST_LIST_VM_DETECTION_OUTPUT
   | }).do_request().as(resp, resp.Body.as(xml, bytes(xml).decode_xml('qualys_api_2_0').as(body, {
   | ..................^,
  Processor json with tag json_message in pipeline logs-qualys_vmdr.asset_host_detection-4.0.0 failed with message: field [message] not present as part of path [message]
]

```

For user activity it fails for each request with:

```auto
[
  failed eval: ERROR: <input>:14:21: csv: record on line 2: wrong number of fields
   | }).do_request().as(resp,
   | ....................^,
  Processor 'conditional' with tag 'fail_on_cel_error' failed with message 'CEL program returned an error. Skipping ingest pipeline execution.'
]

```

Thank you

---

<div class="post-metadata">

**Author:** ![kcreddy](https://avatars.discourse-cdn.com/v4/letter/k/6f9a4e/32.png) [@kcreddy](https://discuss.elastic.co/u/kcreddy)\
**Post date:** [July 18, 2024, 9:39am UTC](https://discuss.elastic.co/t/qualys-vmdr-bug/362777/4 "2024-07-18T09:39:18Z")

</div>

There were few bug fixes and improvements in recent Qualys integration version `4.1.1`. Can you confirm if you are able to fix above issues by upgrading to latest version?

If not, it would be nice to have the sanitized API response by removing sensitive data. You can do so with `Enable request tracing` integration option. This captures the API request/responses to Elastic Agent's `logs` folder.

---

<div class="post-metadata">

**Author:** ![djkprojects](https://avatars.discourse-cdn.com/v4/letter/d/d2c977/32.png) [@djkprojects](https://discuss.elastic.co/u/djkprojects)\
**Post date:** [October 28, 2024, 9:02am UTC](https://discuss.elastic.co/t/qualys-vmdr-bug/362777/5 "2024-10-28T09:02:53Z")

</div>

Hello,

After weeks of trying this we decided to use filebeat directly however we are facing a similar issue when calling Qualys API. As imple CEL program:

get("[API Notification](https://qualysapi.qualys.eu/api/2.0/fo/scan/?action=list%22).with(%7B%22Header)":{  
"Authorization": "Basic "+string(base64("\*\*\*\*\*\*\*\*\*")),  
"X-Requested-With": "filebeat"  
}})

fails with:

failed eval: ERROR: :1:4: http: read on closed response body  
| get("[API Notification](https://qualysapi.qualys.eu/api/2.0/fo/scan/?action=list%22).with(%7B%22Header)":{  
| ...^

We tried this with [amazon.com](http://amazon.com) domain and it failed as well but not with [www.amazon.com](http://www.amazon.com) which makes me wonder if it's the CEL library for filebeat not taking 301 or 302 redirects into consideration?

---

<div class="post-metadata">

**Author:** ![clement-fouque](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clement-fouque/32/83798_2.png) [@clement-fouque](https://discuss.elastic.co/u/clement-fouque)\
**Post date:** [December 23, 2024, 9:55pm UTC](https://discuss.elastic.co/t/qualys-vmdr-bug/362777/6 "2024-12-23T21:55:55Z")

</div>

Can you disable keep xml and see if it's working?
