FAQs for Configurations in Splunk

This topic helps you to find the frequently asked questions related to configuration in Splunk.

Can I configure multiple Qualys accounts?

Yes. You can add multiple accounts under Configuration > Account. Each data input can be assigned to a different account. This is useful when you have multiple Qualys subscriptions or platforms.

What happens if I leave the username and password blank when editing an account?

The existing stored credentials are retained. You only need to re-enter credentials if you want to change them.

Can I use the same account for both VMDR and WAS inputs?

Yes, a single account can be selected for multiple inputs of either type.

What Splunk index should I use?

The default is main. but can create a dedicated index (for example. qualys) to keep Qualys data separate. Create the index in Splunk first (Settings > Indexes > New Index) and then select name in the Index field when creating the data input

Where is the Checkpoint Stored?

All checkpoints are stored in KV Store collections with the following naming pattern:

TA_Qualys_Cloud_Connector_checkpointer_<module>

App-Specific Collections

Separate checkpoint collections are maintained for each module to ensure independent tracking:

  • VMDR Module

    TA_Qualys_Cloud_Connector_checkpointer_vmdr

  • WAS Module

    TA_Qualys_Cloud_Connector_checkpointer_was

Manage KV store collections and data with the Splunk REST API

Related Topics

Troubleshooting

Application Management