Asset Inventory OS Version Not Updated After Latest Scan

This topic includes information on why the latest OS version detected in a scan does not update in the Qualys Asset Inventory and how to update it using authenticated scans or Cloud Agent.

Problem

After you update the operating system on an asset and run a new scan, the latest OS version may appear in the scan results but not in the Asset Inventory under modules such as CyberSecurity Asset Management (CSAM) or Global Asset View (GAV).

For example, a VMware ESXi asset is upgraded to VMware ESXi 7.0.3 build 20328353. After the latest scan runs successfully, the scan detects the updated OS version, but the Asset Inventory still displays the older version, such as VMware ESXi 6.7.0 build.

You may observe the following:

  • The OS version shown in Asset Inventory does not match the latest scan result.
  • The updated OS version appears in the QID 45017. Operating System Detected scan result.
  • Modules such as CSAM or GAV continue to display the older OS version after the scan completes.

Cause

This behavior usually occurs when you perform an unauthenticated scan after updating the operating system on the target asset.

An unauthenticated scan can detect the updated OS version using methods such as TCP/IP fingerprinting. However, it does not update the OS information stored in the Asset Inventory.

By design, Qualys updates the Asset Inventory OS details only when:

  • You run an authenticated scan using a Qualys scanner.
  • The asset reports data through the Qualys Cloud Agent.

Unauthenticated scans do not update Asset Inventory OS details.

Solution

To update the OS version in Asset Inventory, use one of the following methods:

Option 1: Run an authenticated scan on the asset using a Qualys scanner.

  1. Go to Scans > Scans and click New > Scan.

  1. Enter a scan title and select the target asset IP address or range.
  2. Go to Scans tab> Option Profile section.  
  3. Choose an Option Profile that has authentication enabled and valid Windows/Unix authentication records configured.
  4. Click Launch and wait for the scan to complete.
  5. After the scan finishes, go to Assets > Asset Search.
  6. Search for the asset using the IP address or hostname, then open the asset details.
  7. Check the Operating System field to verify that the updated OS version is displayed.

Option 2: Scan the asset using the Qualys Cloud Agent.

  1. Go to Cloud Agent > Agent Management.
  2. Locate the asset and verify that the Agent Status shows Connected.
  3. Now, in the VM module, go to Assets > Asset Search.
  4. Search for the asset using the IP address or hostname.
  5. Open the asset details and check the Operating System field.

The Cloud Agent automatically updates the asset OS version with the latest system changes.