Configure Connectors
Configuring connectors is the third of the three onboarding steps in ETM. A connector brings findings, such as vulnerabilities and misconfigurations, from third-party security and IT tools into ETM. A CSV connector does this with CSV (comma-separated values) files: you map the columns in the file to fields in ETM, so the findings are imported automatically.
Before You Begin
Have the following ready:
- Completed Define Business Entities (Step 2 of onboarding).
- A CSV file of findings exported from the vendor tool that you want to connect.
- The type of findings in the file: vulnerabilities or misconfigurations.
- The severity values or ratings that the vendor uses, so you can map them to Qualys severity levels.
Create a CSV Connector
The connector page has six sections. Complete them in order. Select a section to jump to it.
- Section 1Basic Details
- Section 2Data Model
- Section 3Transform Maps
- Section 4Scoring
- Section 5Identification Rules
- Section 6Review and Confirm
1. Basic Details
Name the connector and tell ETM what kind of data it brings in.
- Enter the connector Name and Description.
- Select the Finding type (Vulnerability or Misconfigurations) and the Vendor.
- (Optional) Select the Preserve the status of absent findings check box.
The following screenshot displays the Basic Details fields:

Field details: Field Reference > Basic Details.
2. Data Model
A data model tells ETM how your CSV file is structured, so the data imports correctly.
- Enter a unique name for the data model.
- Upload your CSV file.
- Set the file format options: Header, Column Delimiter, Qualifier, Row Delimiter, Escape Character, and Header Row.
The following screenshot displays the Data Model fields for the Upload option:

Field details: Field Reference > Data Model.
3. Transform Maps
A transform map connects the fields in your CSV file to the matching fields in ETM.
- Enter the Transform Map Name, and select the Source Data Model and Target Data Model.
The following screenshot displays the Transform Map fields:

- In the Fields Mapping section, select the Source Field, its Data Type, and the Target Field.
- Click Add. The mapping appears below the section, so you can check it and make changes.
Field details: Field Reference > Transform Maps.
4. Scoring
Map the vendor's scores for non-CVE vulnerabilities to the Qualys Detection Score (QDS).
- Fill in all five rows of the score map, one for each Severity level from 1 (least severe) to 5 (most severe). For each row, enter the Expected Source Values and the QDS.
The following screenshot displays the Scoring section:

- Below the score map, select a Default Severity.
Field details: Field Reference > Scoring.
5. Select Identification Rules
Identification rules are ready-to-use precedence rules from Qualys CSAM. The connector identifies findings based on the order of the selected rules.
You can go to the next section without making any changes. To stop using a rule, turn off the toggle next to it. At least one rule must stay selected.

To learn more about these rules, see the CSAM Online Help.
6. Review and Confirm
Check the settings in all the previous sections. Make sure that the details are correct and complete, and then confirm the setup to finish configuring the CSV connector.
Save and Run the Connector
- Save and run the connector. A dialog box appears.
- Select the transform map that defines how the data in the CSV file is transformed.
- Upload the CSV file that contains the data.
The connector then transforms and imports the data based on your settings.
Field details: Field Reference > Save and Run.
Field Reference
Select a tab to see what each field on the CSV connector page is used for.
| Field | Description |
|---|---|
| Name | The name of the connector. |
| Description | A short explanation of what the connector imports. |
| Finding type | The type of findings to import or export: Vulnerability or Misconfigurations. |
| Vendor | The vendor whose data format the connector supports, such as MS Defender or Palo Alto Prisma Cloud. |
| Preserve the status of absent findings | Optional. When selected, findings that do not appear in a new connector run keep their previous status. When cleared, these findings are marked as Fixed. |
| Field | Description |
|---|---|
| Data model name | A unique name that helps you find and manage the data model. |
| Upload | The CSV file that contains your data. |
| Header | Whether the CSV file has a header row. This row usually contains the column names. |
| Column Delimiter | The character that separates columns, such as a comma (,), a semicolon (;), or a tab. |
| Qualifier | The character that encloses each field, usually a double quotation mark ("). |
| Row Delimiter | The character that separates rows, usually a new line (\n). |
| Escape Character | The character that escapes special characters, usually a backslash (\). |
| Header Row | The row number where your data begins. Use this when the top rows of the file contain metadata or comments. |
| Field | Description |
|---|---|
| Transform Map Name | A unique name for the transform map. |
| Source Data Model | The data model that the data comes from. |
| Target Data Model | The data model that receives the data. It defines how the data is structured after it is transformed. |
| Source Field | The field in the source data model that holds the data to map. |
| Data Type | The data type of the source field, such as string, integer, or date. |
| Target Field | The field in the target data model that receives the data. |
| Field | Description |
|---|---|
| Expected Source Values | The vendor's score or rating. Values can be letters or numbers, such as High, Critical, A, or 3. |
| Severity | The Qualys severity levels 1 to 5. This column is already filled in. Map the source values so that they use all five levels. |
| QDS | The Qualys Detection Score, from 0 to 100. A higher number means a higher severity. |
| Default Severity | A severity from 1 to 5 that ETM uses when a vendor score does not match any value in the Expected Source Values column. |
| Field | Description |
|---|---|
| Select Transform Maps | The transform map that defines how the data in the CSV file is transformed. |
| Upload CSV File | The CSV file that contains the data. The file must match the structure of the selected data model. |
Frequently Asked Questions
What happens to findings that are missing from a new connector run?
It depends on the Preserve the status of absent findings check box. When selected, these findings keep their previous status. When cleared, they are marked as Fixed.
What if a vendor score does not match my score map?
ETM applies the Default Severity that you select below the score map.
Do I have to change the identification rules?
No. You can go to the next section without making changes. If you turn off rules, at least one rule must stay selected.
Can I add connectors for other tools later?
Yes. After onboarding, you can view and manage connectors from the Configuration > Connectors tab.
After you complete all three onboarding steps, you can view the supported connectors from the Configuration > Connectors tab.