Linking Checkmarx (Checkmarx One) as a source
Let AI connect your sources for you
Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

This source is currently in alpha. The interface and available tables may change.
The Checkmarx (Checkmarx One) connector syncs projects, applications, scans, and more into the PostHog data warehouse, so you can analyze them alongside your product data.
Prerequisites
Credentials that can read the data you want to sync. PostHog only reads data, so read access is enough.
Adding a data source
- In PostHog, go to the Sources tab of the data pipeline section.
- Click + New source and click Link next to this source.
- Enter your credentials (see Configuration below) and click Next.
- Select the tables you want to sync, choose a sync method and frequency, then click Import.
Once the syncs are complete, you can start querying this data in PostHog.
Enter your Checkmarx One credentials to automatically pull your application security data.
You can generate an API key in Checkmarx One under Settings → Identity and Access Management → API Keys. The tenant name and region are shown in your Checkmarx One URL (for example, a tenant on https://eu.ast.checkmarx.net is in the EU region).
You'll be asked for:
- Tenant name: for example
your-tenant. - Region: choose between US (ast.checkmarx.net), US2 (us.ast.checkmarx.net), EU (eu.ast.checkmarx.net), EU2 (eu-2.ast.checkmarx.net), Germany (deu.ast.checkmarx.net), ANZ (anz.ast.checkmarx.net), India (ind.ast.checkmarx.net), Singapore (sng.ast.checkmarx.net) and UAE (mea.ast.checkmarx.net).
- API key
Sync modes
Each table can be synced in one of several modes, depending on what the source supports:
- Webhook (when available) – the source pushes changes to PostHog in real time. Fastest freshness, lowest ongoing cost, and the only mode that reliably captures updates and deletes.
- Incremental – only new or updated rows are synced on each run, using a cursor field (such as an
updated_attimestamp). Cheaper than a full refresh, but deletes aren't captured. - Append only – new rows are appended using a cursor field; existing rows are never updated. Ideal for immutable, append-only tables like event logs.
- Full refresh – the whole table is reloaded on every sync. Use it when a table has no reliable cursor or when you need deletions reflected.
See sync methods for a full explanation of how each mode works and how to choose between them.
All Checkmarx (Checkmarx One) tables are full refresh. Each sync replaces the contents of the table.
Configuration
| Option | Type | Required |
|---|---|---|
Tenant name | text | Yes |
Region | select | Yes |
API key | password | Yes |
Supported tables
| Table | Description | Sync method | Incremental field | Primary key |
|---|---|---|---|---|
projects | A Checkmarx One project, the unit that groups scans of a single code repository or component. | Full refresh | — | — |
applications | A Checkmarx One application, a business-level grouping of related projects. | Full refresh | — | — |
scans | A scan run in Checkmarx One, including its status and the engines (SAST, SCA, KICS, etc.) it executed. | Incremental, Full refresh | createdAt | — |
scan_results | Fetched per scan. Incremental syncs pull data for scans created since the last sync (with a 7-day overlap so late-finishing scans and recent triage changes are picked up) | Incremental, Full refresh | scan_created_at | — |
scan_results_summary | Fetched per scan. Incremental syncs pull data for scans created since the last sync (with a 7-day overlap so late-finishing scans and recent triage changes are picked up) | Incremental, Full refresh | scan_created_at | — |
application_rules | Fetched once per row in the applications table | Full refresh | — | — |
sast_predicates_changelog | Fetched once per row in the projects table | Full refresh | — | — |
result_states | The built-in triage states a finding can be assigned, which decode the state column on scan_results. | Full refresh | — | — |
result_statuses | The statuses a finding can carry relative to the previous scan, which decode the status column on scan_results. | Full refresh | — | — |
result_severities | The severities a finding can carry, which decode the severity column on scan_results. | Full refresh | — | — |
custom_states | A triage state defined by your tenant, in addition to the built-in states in result_states. Includes states that have since been deleted, so findings left in one still resolve to a name. | Full refresh | — | — |
Troubleshooting
- If the connection fails with an authorization error, the API key is wrong, expired, or has been revoked. Create a new one, then reconnect the source.
- If a table syncs no rows, the credential may not have access to that data. Check its permissions, then reconnect the source.
If your sync is failing or data looks wrong, see the Data warehouse troubleshooting guide. If that doesn't help, contact support – we're happy to help.