Connector Centralization 3.4.0
May 22, 2026
ETM Connectors 3.4.0 delivers an enhanced connector creation experience along with expanded asset class and misconfiguration findings coverage across multiple cloud security connectors. The release focuses on simplifying setup, improving validation and visibility, and broadening supported cloud resources.
Enhanced Connector Creation Workflow
The connector creation experience has been redesigned with a clear, multi‑step workflow that guides administrators through setup with improved in‑product guidance, validation checks, and advanced configuration options.
Setup Guide
A new Setup Guide tile appears as the first step in the connector setup flow. It provides connector‑specific reference information, including:
- Overview of connector functionality
- Authentication details
- Data ingestion scope
- Pre‑configuration checklist
- Quick links to authentication setup, permissions, troubleshooting, and documentation

This information is available before configuration begins, helping users prepare correctly.
Test Connection Validation
The Test Connection feature now runs a structured five‑step validation sequence before saving a connector:
- Network Reachability — Verifies that the connector endpoint is reachable over HTTPS (port 443).
- TLS Handshake — Confirms that a secure TLS connection can be established with the remote endpoint.
- Authentication Credential Check — Validates the configured credentials against the source system's authentication endpoint.
- Authorization Scope Check — Confirms that the provided credentials have the required permissions to access the configured data scope.
- Data Fetch — Verifies that data can be successfully retrieved from the source system using the configured connection.
![]()
Validation results are displayed inline, allowing administrators to identify and resolve issues early in the setup process.
Scope and Schedule Enhancements
The Scope and Schedule page has been redesigned with a cleaner layout and improved defaults:
- Data to Sync: Choose between syncing Assets and Findings or Assets only
- Default Schedule: Connectors default to a Daily schedule, with options for custom single or recurring runs
- This Connector Pulls Panel: Displays the exact asset types and findings that will be ingested
- Advanced Settings Toggle: Disabled by default and enabled as needed

Advanced Settings
When enabled, Advanced Settings provide additional configuration options:
- Filters: Connector‑specific filters.
- Data Staging Configuration: Controls the automatic or manual synchronization of staging data with downstream systems
- Transformation Map: View default Qualys‑provided asset class mappings
Sampling Mode
A new “Limit sync to top 1,000 assets and findings” option allows users to validate connector output before enabling full synchronization. The Sampling Mode restricts data ingestion to a targeted subset of up to 1,000 assets and their associated findings. This helps you quickly validate integration and review meaningful security data without a full environment sync.
When selected, the connector applies risk-based filters during asset fetch to ensure the ingested subset represents the most relevant assets in your environment rather than a random or arbitrary sample.
Sampling Mode is supported for:
- CrowdStrike Endpoint Security
- Palo Alto Networks Prisma Cloud (CWPP)
- Wiz (VM Assets)
- Microsoft Defender for Endpoint v2
AIS Rule Selection Option Updated
The AIS rule selection step has been updated to simplify asset identification and rule management.
- You are no longer required to manually select AIS rules within the connector wizard.
- AIS rules can now be configured and managed directly within the CSAM module.
You can navigate to the Rules section in CSAM to create and manage rules specific to their connectors.
Asset Identification Behavior:
- Cloud-based assets: The AIS engine automatically uses unique cloud provider identifiers (for example, AWS ARN) for accurate asset identification.
- Host-based assets: You are expected to define appropriate identification rules within the CSAM module.
For some subscriptions, we are selectively deploying the new machine learning-based AIS engine. In such cases, rule selection and configuration are handled automatically, eliminating the need for manual rule creation.
Expanded Asset Class and Findings Support for Misconfigurations
Additional asset classes and misconfiguration findings are now supported across multiple connectors. This enhancement expands the coverage of asset and findings you can view in ETM.
Orca Cloud Security
- Compute (AWS EC2, Azure VM, GCP Compute, OCI VM)
- Serverless (AWS Lambda, Azure Functions, GCP Cloud Functions, OCI Functions)
- Container Instances (ECS/Fargate, ACI, GKE Pods, OCI Container Instances)
- Container Images (ECR, ACR, Artifact Registry, OCIR)
Cortex Cloud by Palo Alto Networks
- Identity – User (AWS IAM User, Azure User, OCI IAM User)
- Identity – Role (AWS IAM Role, Azure Role Definition, GCP Role)
- Identity – Group (AWS IAM Group, Azure Group, OCI IAM Group)
Palo Alto Networks Prisma Cloud (CSPM)
- Serverless (AWS Lambda, GCP Cloud Function, OCI Function)
- Compute (OCI Compute Instance)
Wiz (Cloud Security)
- Identity – User
- Identity – Role
- Identity – Group
- Network (AWS, Azure, GCP, OCI Virtual Networks)