About Scanner Replacement Automation

Qualys is deprecating legacy, non-Oracle Linux (OEL)-based scanner appliances and older scanner software versions. The Scanner Replacement Automation toolkit is a self-service utility that helps you identify legacy, non-OEL, and end-of-support (EOS) Qualys scanner appliances in your subscription and replace them with current Oracle Linux (OEL)-based scanner appliances, with minimal manual effort.

Because the scanner appliance architecture does not support in-place operating system upgrades, moving to a new scanner image requires deploying a new appliance and transitioning your existing configuration to it. The toolkit automates that transition so that asset groups, scheduled scans, network settings, and other configurations follow the new appliance automatically.

The toolkit is provided by Qualys as a self-service utility to assist with scanner appliance migrations. Test replacements in a non-production environment before running them against production scanners.

What This Guide Covers

This guide explains how to install the toolkit, connect it to your Qualys subscription, assess your scanner inventory, and run scanner replacements—either with automatic VM deployment on VMware vSphere or AWS, or using generated infrastructure-as-code (IaC) templates that you deploy yourself.

When to Use This Toolkit

Use Scanner Replacement Automation when you need to migrate legacy, non-Oracle Linux (OEL)-based or EOS scanner appliances to the current OEL-based scanner appliance release:

  • Scanner appliance versions up to 3.10.x are built on a non-Oracle Linux base and are nearing end of support (EOS).
  • Scanner appliance versions 4.1 and later are built on Oracle Linux (OEL) and are the current, supported release line.

The replacement steps are the same regardless of which legacy version you are migrating from.

How It Works

The toolkit walks each scanner replacement through four stages:

  1. Assess – Connects to your Qualys subscription and identifies scanner appliances that need replacement (legacy, non-OEL, EOS, or running outdated software).
  2. Plan – Shows a prioritized replacement dashboard with a recommended action for each scanner.
  3. Deploy – Optionally provisions a new Oracle Linux (OEL)-based scanner VM on VMware vSphere or AWS for you, or generates infrastructure-as-code templates you can run yourself.
  4. Replace – Creates the new scanner appliance record in Qualys, waits for it to come online, transfers configuration from the old appliance using the Qualys Replace Scanner Appliance API, and—if you choose to—decommissions the old appliance.

Benefits

  • Identify every legacy, non-OEL, and EOS scanner appliance in your subscription from a single dashboard.
  • Replace one scanner appliance, or many at once, without manually re-creating asset group and scan schedule associations.
  • Deploy replacement scanner VMs automatically on VMware vSphere or AWS, or generate ready-to-run templates for other platforms.
  • Track replacement progress in real time and roll back a failed replacement before configuration is transferred.

Additional References

Refer to the following links for additional information: