Linking Qualys VMDR as a source

Let AI connect your sources for you

Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

Learn more
PostHog Wizard hedgehog

Alpha release

This source is currently in alpha. The interface and available tables may change.

The Qualys VMDR connector syncs hosts, host list detection, scans, and more into the PostHog data warehouse, so you can analyze them alongside your product data.

Prerequisites

Credentials that can read the data you want to sync. PostHog only reads data, so read access is enough.

Adding a data source

  1. In PostHog, go to the Sources tab of the data pipeline section.
  2. Click + New source and click Link next to this source.
  3. Enter your credentials (see Configuration below) and click Next.
  4. Select the tables you want to sync, choose a sync method and frequency, then click Import.

Once the syncs are complete, you can start querying this data in PostHog.

Enter your Qualys API credentials to sync your VMDR vulnerability management data.

Use your account's regional API server URL (for example qualysapi.qualys.com, qualysapi.qg2.apps.qualys.com, or qualysapi.qualys.eu) - you can find it under Help > About in the Qualys UI. The user needs API access enabled (a Manager role, or a role granted API access).

The knowledge_base table additionally requires the KnowledgeBase download option to be enabled on your Qualys subscription. On API version 4.0 it also needs your account's gateway URL (for example gateway.qg2.apps.qualys.com), which you can find under Help > About in the Qualys UI. Leave the gateway URL blank if you do not sync the knowledge_base table.

You'll be asked for:

  • API server URL: for example qualysapi.qualys.com.
  • Username
  • Password

Sync modes

Each table can be synced in one of several modes, depending on what the source supports:

  • Webhook (when available) – the source pushes changes to PostHog in real time. Fastest freshness, lowest ongoing cost, and the only mode that reliably captures updates and deletes.
  • Incremental – only new or updated rows are synced on each run, using a cursor field (such as an updated_at timestamp). Cheaper than a full refresh, but deletes aren't captured.
  • Append only – new rows are appended using a cursor field; existing rows are never updated. Ideal for immutable, append-only tables like event logs.
  • Full refresh – the whole table is reloaded on every sync. Use it when a table has no reliable cursor or when you need deletions reflected.

See sync methods for a full explanation of how each mode works and how to choose between them.

All Qualys VMDR tables are full refresh. Each sync replaces the contents of the table.

Configuration

OptionTypeRequired
API server URLtextYes
UsernametextYes
PasswordpasswordYes
Gateway URLtextNo

Supported tables

TableDescriptionSync methodIncremental fieldPrimary key
hosts

Asset inventory: one row per host in the Qualys subscription, with tracking method, OS, and last-scan timestamps.

Incremental, Full refreshlast_vuln_scan_datetime—
host_list_detection

Per-host vulnerability detections: one row per (host, detection) with status, severity, and first/last found timestamps — the core VMDR remediation feed.

Incremental, Full refreshlast_update_datetime—
scans

VM scan history: one row per vulnerability scan with launch time, state, and target.

Incremental, Full refreshlaunch_datetime—
knowledge_base

Requires the KnowledgeBase download option enabled on your Qualys subscription

Incremental, Full refreshlast_service_modification_datetime—

Troubleshooting

  • If the connection fails with an authorization error, the password is wrong, expired, or has been revoked. Create a new one, then reconnect the source.
  • If a table syncs no rows, the credential may not have access to that data. Check its permissions, then reconnect the source.

If your sync is failing or data looks wrong, see the Data warehouse troubleshooting guide. If that doesn't help, contact support – we're happy to help.

Still have questions?

Was this page useful?