Service Graph Connector for Qualys release notes
Summarize
Summary of Service Graph Connector for Qualys release notes
The Service Graph Connector (SGC) for Qualys is a ServiceNow-developed integration designed to import hardware assets from Qualys into the ServiceNow Configuration Management Database (CMDB) efficiently and securely. It supports two Qualys APIs—Global Asset View API (requires CASM license) and Qualys Asset Management and Tagging API (no CASM license required)—allowing flexibility depending on customer licensing.
Show less
The release notes detail version history, highlighting enhancements, fixes, and feature additions aimed at improving data accuracy, security compliance, and performance.
Key Features and Enhancements
- Version 2.1.0 (June 2026): Security enhancements with Query Access Control Lists (ACLs) added across 13 Qualys SGC tables, including asset details, NIC details, open ports, processors, services, software, and tagging information, aligning with ServiceNow Platform Security best practices. The admin role was refined to sgcadmin for granular control and includes Guided Setup access.
- Version 2.0.9 (October 2025): Fixed population of manufacturer details and synchronization of Qualys SGC objectid with other discovery sources for Azure VMs. Unnecessary attributes are now excluded for cleaner data ingestion.
- Version 2.0.7 to 2.0.5: Various fixes including removal of problematic custom attribute fields, improved network adapter and serial number mappings, hostname cleansing before ingestion, and enhanced performance for software data ingestion.
- Version 2.0.3 (November 2024): Added support for Google Cloud Platform (GCP) asset mapping. Optimized imports to exclude certain large data sets by default to prevent memory issues. Improved handling of special characters in credentials and multi-instance configurations.
- Versions 2.0.2 to 2.0.1: Bug fixes addressing relationships between servers and VMs, error handling, software data import options for large datasets, and improved data source testing capabilities.
- Version 2.0.0 (February 2024): Initial release as part of ServiceNow’s Service Graph Connector suite, supporting seamless and secure import of Qualys hardware asset data into the CMDB.
Practical Implications for ServiceNow Customers
Customers leveraging the Service Graph Connector for Qualys can expect improved security compliance through granular ACL controls, enhanced data accuracy with fixes to manufacturer and asset relationship mappings, and better performance during large data imports. The ability to select between two Qualys APIs based on licensing allows flexibility in deployment.
Regular updates address operational issues such as encoding special characters in credentials, handling multi-instance configurations, and preventing memory overloads during imports—ensuring a stable and efficient integration experience.
Admin role refinement enhances governance and access control, supporting enterprise security policies.
Version history for the Service Graph Connector for Qualys application on the ServiceNow Store.
Version history
- Version 2.1.0 - June 2026
- The following enhancements and changes support internal security directives:
- Query ACLs added across 13 Qualys SGC tables: asset details, NIC details, open port details, processor details, service details, software details, asset tags and cloud tags, computer/hardware CI mapping rules, and asset-import staging to align with ServiceNow Platform Security guidance.
- The admin role for the Qualys SGC ACLs is replaced by the sgc_admin role for more granularity. The sgc_admin role additionally inherits the sn_help_setup_player role to preserve the Guided Setup access.
- The following enhancements and changes support internal security directives:
- Version 2.0.9 - October 2025
-
- Fixed:
- Manufacturer details are populated in the Qualys Service Graph Connector (SGC) as expected.
- The Qualys SGC object_id is synchronized with other Discovery Sources for Azure Virtual Machines (VMs).
- Unnecessary attributes retrieved by the Qualys SGC are ignored.
- Fixed:
- Version 2.0.7 - June 2025
- Fixed: Removed the Custom attributes field from the service graph connector's import so it no longer causes problems with the payload.
- Version 2.0.6 - February 2025
-
- Fixed:
- Network adapter mapping.
- Added serial number mapping.
- Fixed:
- Version 2.0.5 - December 2024
-
- Fixed:
- The hostname is now cleansed before ingesting by Qualys SGC
- Addressed performance issue for software ingestion for Global API.
- Fixed:
- Version 2.0.3 - November 2024
-
- New: Mapping for Google Cloud Platform (GCP) Assets.
- Fixed:
- Certain information such as open ports, volumes, tags, and software is not imported by default to address memory problems with the Asset Management API for the Qualys Service Graph Connector.
- Special characters such as '%' are encoded so if included in the credentials they do not impact Connection tests.
- Issues related to multi-instance functionality that permits you to configure multiple instances of Qualys in the Service Graph Connector.
- Version 2.0.2 - October 2024
-
- Fixed:
- The relationship between server and virtual machine.
- Various unhandled errors.
- Fixed:
- Version 2.0.1 - August 2024
-
- Fixed:
- You have the option to include or exclude software data for large imports.
- Data source improvements so that Test load 20 records' imports a maximum of 20 records.
- Fixed:
- Version 2.0.0 - February 2024
- This integration is part of ServiceNow-developed Service Graph Connectors. The Service Graph Connector for Qualys imports hardware assets from the Qualys product to the ServiceNow CMDB quickly, seamlessly, and securely. This service graph connector integration was developed by ServiceNow Engineering.
- Two Qualys APIs are supported for importing data. Choose one and update a system property to activate it.
- Global Asset View API -A CASM license is required.
- Qualys Asset Management and Tagging API -A CASM license is not required.