Creating a Compute Scan Recipe with a Qualys Agent
Create a Compute (host) scan recipe using your own Qualys license and then view the results in the Console or the Qualys dashboard.
Complete the following prerequisites before creating a Compute scan recipe with a Qualys agent.
-
Create an account in Qualys with a license to use VMDR. You must have a Qualys account with a license to use VMDR before you can create a Compute scan recipe with a Qualys agent. See the Qualys VMDR sign-up page to get started. After you have a license, you must generate a Cloud Agent Activation Key, and enable OCI for the agent. Perform these tasks using the Qualys platform. See the Qualys Cloud Platform documentation for instructions.
-
Create a dynamic group. Create a dynamic group of instances that you want to scan. See Managing Dynamic Groups.
-
Write policies. Write Agent-Based Standard Policies and Agent-Based Qualys Policies. See Required IAM Policy for Compute Scanning Recipes.
-
Create a vault. Create a vault to store your Qualys license information. See Managing Vaults.
-
Define a secret. Create a secret to store your Qualys license information in the vault. See Defining a Secret for a Compute Scan Recipe.
- Review the following important information about Qualys scans:
- After you create an OCI agent or Qualys agent Compute scan recipe, don't change that recipe to change agents. Create another recipe.
-
Qualys performs scans OCI hosts every four hours. Scanning OCI hosts count toward your Qualys license usage. Contact Qualys for any issues with your license or usage.
- Viewing Qualys scan results:
-
View Qualys scan results in the Qualys portal about four hours after you’ve created the new scan target.
-
View Qualys scan results in the OCI Console within 12 hours of creating the new scan target.
-
To create a Compute scan recipe with a Qualys agent, complete the following steps:
After creating a recipe, you can create scan targets and associate them with the recipe. See Creating a Compute Target.