Best approach to limit CI discovery from Qualys VR integration based on a specific Qualys Tag
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
2 hours ago
Hello Community,
I'm looking for recommendations on the best way to limit the CIs discovered by the ServiceNow Vulnerability Response (VR) integration with Qualys based on a specific Qualys Tag.
Our goal is to prevent assets associated with a particular Qualys Tag from being discovered or created as CIs in ServiceNow.
The main reason is to reduce the number of discovered CIs and optimize our licensing costs, since these assets are not relevant for our CMDB or Vulnerability Response processes.
Has anyone implemented a solution like this?
Specifically, I'm interested in understanding:
- Is there a supported way to exclude assets based on a Qualys Tag before they are processed by ServiceNow?
- Can this be achieved through the Qualys integration configuration, API filters, Transform Maps, Identification Rules, or another supported mechanism?
- What is considered the best practice to prevent these CIs from being created while maintaining a supported integration?
- Are there any limitations or potential side effects of filtering assets in this way?
For example, we'd like to exclude all assets that belong to a specific Qualys Tag, so they are never imported into ServiceNow and therefore do not create or update CIs.
If anyone has implemented this approach or can share documentation or recommendations, I would greatly appreciate your guidance.
Thank you!