Asset Deduplication and Reconciliation (Purging)
One host can reach your inventory through several sensors and connectors, each creating its own record. Three rule types work together to collapse those records into one accurate asset: identification rules decide what counts as the same asset, the reconciliation rule merges the matches, and purge rules remove the records you no longer track.
Navigate to: Inventory > Rules
Use this to
- Work out why the same host appears more than once in your inventory.
- Choose the attributes that decide whether two records are the same asset.
- Understand which source wins when records disagree.
- Decide which of the three rule types to configure next.
Understand Duplicate Assets
A duplicate is more than one inventory record for the same physical or virtual host. Each record is accurate about what its own source saw. The problem is that they describe one machine, so its risk is counted twice, its software is listed twice, and a scan that covers it once appears to have missed it.
Take the scenario the reconciliation rule is built for. An IP scan and a ServiceNow scan each identify an asset with the same IP address, and the ServiceNow scan found its asset first. Without reconciliation, your inventory holds two records for one host.
The records are not equal. Where a record comes from decides what it holds and what happens to it when a rule runs.
| Record type | What it is |
|---|---|
| Managed asset | An asset a Qualys native sensor has seen, such as the Qualys agent or the scanner. It carries scan and agent data of its own. |
| Unmanaged asset | An asset that comes only from a third-party connector. No Qualys sensor has reported it. |
| Asset from several connectors | One asset carrying data from more than one connector source. Each source contributes its own data to the same record. |
Why Duplicate Assets Occur
Duplicates are a normal result of discovering the same environment several ways. These are the common causes.
| Cause | What happens |
|---|---|
| Sensors run on different schedules | A third-party source identifies an asset, and a Qualys native sensor discovers the same host again on its own schedule. Each creates a record. |
| Several connectors report one host | Active Directory, ServiceNow and Webhook connectors can each know the same machine under their own identifiers. |
| Tracking methods differ | Scan-based assets are tracked by IP, DNSNAME or NETBIOS. Two scans that track the same host by different methods do not recognise each other's records. |
| An agent is re-provisioned | When a purge rule re-provisions the agent instead of uninstalling it, the agent creates a new asset. The old record stays until something removes it. |
| Cloud instances are rebuilt | A terminated instance keeps its record while its replacement is discovered as a new asset, which is why the default purge rules target terminated AWS, Azure and GCP assets. |
One more cause worth confirming with engineering: in DHCP ranges an IP address that moves to a different host between scans can produce records that look like one asset, or split one asset across two records. If that is accurate, it is an argument for matching on a stable attribute rather than on IP alone.
How ETM Identifies Duplicates
Deduplication is not a single setting. Three rule types run at different points, and each one does a different job.
| Stage | What happens | Where you set it up |
|---|---|---|
| 1. Identify | An asset identification rule defines the attributes used to decide whether an asset found by a third-party source already exists in Qualys. An asset must match all the selected fields before the rule treats it as the same asset. | View or Create Asset Identification Rules |
| 2. Reconcile | The reconciliation rule merges assets that Qualys native sensors discover with assets that third-party sources already identified, so the duplicate records become one managed asset. It runs on demand, or on a recurring 24-hour schedule with the first run 5 minutes after you configure it. | Configure Reconciliation Rule |
| 3. Purge | Purge rules delete the records you no longer track — stale scan-based assets, terminated cloud instances, connector data for assets that have gone. A purge rule runs at a six-hour interval once created. | Create Asset Purge Rules |
Order matters. Identification rules decide what counts as a match, so review them before you run reconciliation. The rules you define are also offered as selections in the Connectors application, where you specify the attributes required for a given connector.
Matching Attributes
An identification rule is built from fields you move from Available Fields to Selected Fields. Those fields are the attributes the rule uses to identify whether assets found by third-party sources already exist in Qualys.
Two rules govern the choice:
- Match on all, not any — when the rule runs, an asset must match every selected field. Each field you add makes the rule stricter, not broader.
- Keep the set small — select one field wherever you can, or at most two to three closely related fields such as IP and MAC address.
A rule built from many fields matches almost nothing, and the duplicates survive. A rule built from one unstable field matches too much, and unrelated assets are merged.
The attribute table below is drafted from product knowledge, not from existing documentation. Only IP and MAC address are confirmed by the identification rules topic. Please have an SME confirm which fields actually appear in Available Fields, correct the guidance in the second column, and remove any row that does not exist.
| Attribute | When it is a good match key |
|---|---|
| IP address | Static addressing, or a network segment where addresses do not move between hosts. Pair it with MAC address where addresses are assigned dynamically. |
| MAC address | Physical hosts, and virtual machines whose adapters are not regenerated. Stable across an address change, which is why it pairs well with IP. |
| DNS name | Environments with disciplined DNS records. Weak where several names resolve to one host. |
| NetBIOS name | Windows estates where the NetBIOS name is set from a naming standard. |
| Hostname or FQDN | Servers with a controlled naming convention. Weak for workstations that are renamed or re-imaged. |
| Cloud instance ID | AWS, Azure and GCP workloads. The strongest key for cloud assets, because the provider guarantees it is unique. |
| Serial number or asset ID | Hardware inventories and CMDB sources such as ServiceNow, where the same identifier is recorded on both sides. |
Source Precedence
When two records describe one host, something has to decide which record survives and what happens to the data the other one holds. Purge rules make that decision visible, because they behave differently depending on where the asset came from.
| Asset | What a purge rule removes |
|---|---|
| Managed asset | Only the third-party connector data is deleted. The asset itself is not purged, because a Qualys sensor still reports it. |
| Unmanaged asset | The asset is purged when it meets the rule criteria, because the connector was its only source. |
| Asset from several connectors | Only the connector data the rule was created for is purged. The asset is deleted once the data from every connector source has been deleted. |
This behaviour applies to third-party assets discovered by the Webhook, ServiceNow and Active Directory connectors.
The precedence order below is drafted from the purge behaviour above and needs engineering confirmation, in particular whether reconciliation keeps the Qualys record and folds the third-party record into it, or the reverse, and what decides the winner when two attributes disagree.
- Qualys native sensors first — data from the Qualys agent and the scanner takes precedence, because it is collected directly from the host.
- Cloud provider metadata next — authoritative for instance state, region and instance ID, and the basis of the default purge rules for terminated AWS, Azure and GCP assets.
- Third-party connectors last — Active Directory, ServiceNow and Webhook data enriches an asset, and stands on its own only while no Qualys sensor has reported the host.
Order of discovery does not set precedence. In the reconciliation scenario the ServiceNow scan finds the asset first, and the merged result is still a single managed asset.
Work in this order. Check that an identification rule covers the connector source, run the reconciliation rule, then look at the asset list again. Reach for a purge rule only for records that no source is reporting any more, because a purge deletes the matching assets from your inventory when it runs.