Asset Rules

Asset rules decide which software and ports are authorized, which duplicate records are merged, and which assets leave your inventory. Find the rule type you need below and go straight to the task.

Use this to

  • Mark software and ports as authorized, unauthorized, or needs review.
  • Merge the duplicate records of an asset found by several sources.
  • Remove assets you no longer want to keep in your inventory.
Rule type What it does
Software Defines which software is authorized, unauthorized, or needs review, and reports on what is installed in your environment.
Port Marks the ports found on your assets as authorized or unauthorized, and shows the QDS that unauthorized ports contribute to TruRisk™ aggregation.
Asset purge Removes assets you no longer want to keep in your inventory, and reports what each rule run deleted.
Reconciliation Merges the duplicate records that appear when the same asset is discovered by more than one source.
Identification Decides whether an asset from a third-party source already exists in Qualys, using the attributes you choose.

New to this? Asset Deduplication and Reconciliation explains how the identification, reconciliation and purge rules work together to keep one record per host.

If you are setting up rules for the first time, start with the identification and reconciliation rules so that assets from different sources are matched and merged correctly, and then define the software and port rules that report on them.

Software Rules

Port Rules

  • Create Port Rule — Add authorized and unauthorized ports to a rule so that QDS scores attach to the unauthorized ones.
  • View Port Rules — See the port rules you have, including the default External Unsanctioned Ports rule.
  • Reorder Port Rule — Set the priority of your port rules by dragging them where you want them.
  • Manage Port Rule — View, edit, delete, enable, or disable a rule, and alert on unauthorized port installations.
  • View Ports Details — Check the authorization, rule name, rule status, and QDS for each port.

Asset purge rules

  • Create Asset Purge Rules — Purge cloud agent, cloud provider metadata, scan-based, and third-party connector assets that meet your criteria.
  • Default Asset Purge Rules — Review the default purge rules, which are disabled by default, and enable the ones you want.
  • Download Execution Report — Download a CSV report with the details of the assets a purge rule deleted.

Reconciliation Rules

Identification Rules

Software rules and port rules select their assets by tag, so define the asset tags you need before you create these rules.