View or Create Asset Identification Rules

An asset identification rule defines the attributes used to identify whether the assets found by third-party sources already exist in Qualys. Use the Identification tab to view the existing rules and to create a new one.

Navigate to: Inventory > Rules > Identification

Use this to

  • Review the identification rules in your subscription.
  • Match third-party assets against assets already in Qualys.
  • Choose which connector sources a rule applies to.

View asset identification rules

The Inventory > Rules > Identification tab lists the rules in your subscription and gives you three controls:

Control What it does
(a) Create New Rule Creates a new asset identification rule.
(b) Reorder Reorders the asset identification rules.
(c) Reset Retains only the default system-generated asset identification rules.

Create an asset identification rule

Before you begin: Create the connectors whose assets you want the rule to cover. The Rule Applicability section is not visible if no connectors are created.

To create an asset identification rule:

  1. Go to Inventory > Rules > Identification, and click Create New Rule.
  2. Enter the rule name.
  3. Select the checkboxes next to the fields you need in the Available Fields section, and click the single arrow key icon. The fields move to the Selected Fields section. These fields are the attributes the rule uses to identify whether the assets found by third-party sources already exist in Qualys.

    Select one field wherever you can, or at most two to three closely related fields such as IP and Mac Address. When the rule runs, an asset MUST match ALL the selected fields for a match to occur.

    The rules you define here are offered as selections in the Connectors application. For more information, refer to the Asset Identification Rule Selection section. From the Connectors application, specify the attributes required for a given connector.

    To move the selected fields from Available Fields to Selected Fields, click the Single arrow key icon. To move them back, click the Reverse arrow key icon.
    To move all fields from Available Fields to Selected Fields, click the Double arrow key icon. To move them all back, click the Reverse arrow key icon.

  4. Click the arrow next to the connectors you need, and select the connector sources. The assets scanned or discovered by these connectors are identified and imported into the CSAM inventory.

    The Rule Applicability section is not visible if no connectors are created.

    • The checkboxes next to all connectors are selected by default. Clear the checkbox for any connector you do not want to include.
    • VMware ESXi version 1.0.0 is a prerequisite for importing assets scanned by the VMware ESXi connector from CSAM. If the VMware ESXi connector is created from the Qualys Connector application, the ESXI checkbox appears on the Create New Asset Identification Rule page.
  5. Click Create.

    Create rule.

    The rule is created. View its details on the Inventory > Rules > Identification tab, and use the Quick Actions menu of a rule to view, edit, or delete it. To delete several rules at once, select them and choose Delete from the Actions list.

: Give each rule a name that identifies the source and the matching attribute it uses, so that you can tell the rules apart when you reorder them or select them in the Connectors application.