Qualys Vulnerability Management Integration - SaaS

Qualys Vulnerability Management is a cloud-based service that provides immediate, global visibility into where your IT systems might be vulnerable to the latest Internet threats and how to protect them. It helps you to continuously identify threats and monitor unexpected changes in your network before they turn into breaches.

The Qualys VM integration with the Archer IT & Security Vulnerabilities Program use case enables organizations to:

  • Catalog network devices on a corporate network

  • Discover network device vulnerabilities using scanning technology.

  • Supplement the Vulnerability Library with Qualys’ knowledge base.

To learn more, see Qualys Vulnerability Management Integration the Archer Exchange.

Archer Exchange: With the Archer Exchange, the Archer team has created a broad selection of supplemental, value-added offerings to help you get your unique risk management program on the right path, right from the start. You can leverage the Archer Exchange offerings to expand the use of Archer solutions into new business processes and address specific industry, geographic, regulatory, or technical requirements.

Release notes

Release Date

Release Version

Changes
February 2026 Archer 2025.08 The JavaScript Transporter in Data Feed Manager has been updated to use Fetch instead of Request. Fetch is a modern JavaScript API for making HTTP requests, offering a simpler and more powerful alternative to the older Request library.

For more information, see the following blog post: Data Feed Manager JavaScript Transporter Scripts Require Update.

Prerequisites

Components

Requirement

Archer Solution

IT Security Risk Management

Archer Use Case

IT & Security Vulnerabilities Program

Archer Applications

  • Devices

  • Vulnerability Library

  • Vulnerability Scan Results

Requires Archer On-Demand Application (ODA) License

Zero (0) Archer On-Demand Application (ODA) licenses are required for this offering.

Archer requirements

Archer Platform Release 2025.08 and later

Supported Archer Environments

  • Archer SaaS

  • Archer On-Premises

Partner/Vendor Requirements

Valid Qualys license required.

Integration diagram

A diagram of a software issue  Description automatically generated

Configure the Data Feeds

  1. Configure the JavaScript transport settings.

  2. Configure the Qualys VM data feeds

Configure the JavaScript Transporter settings

Before you upload a JavaScript file, you must configure the JavaScript Transporter settings in the Archer Control Panel.

  1. Open the Archer Control Panel.

  2. Go to Instance Management > All Instances.

  3. Select an instance.

  4. On the General tab, go to the JavaScript Transporter section.

  5. In the Max Memory Limit field, set the value to 2048 MB (2 GB).

  6. In the Script Timeout field, set the value to 120 minutes (2 hours).

  7. Require Signature is active by default on install. Signed Certificate Thumbprints are required for all Hosted clients.

    1. In the Signing Certificate Thumbprints section, add a thumbprint for each digitally signed JavaScript file.

      1. In the Signing Certificate Thumbprints section, double-click an empty cell.

      2. Enter the digital thumbprint of the trusted certificate used to sign the JavaScript file.

        Note: For more information on how to obtain digital thumbprints, see "Digital Thumbprints" below.

        Important: If you enable Require Signature and do not specify thumbprints, JavaScript files will not be accepted by the system.

  8. On the toolbar, click Save.

Configure the Qualys VM data feeds

This section provides instructions for configuring the Qualys VM data feeds in the Archer Platform. This document is not intended to suggest optimum installations or configurations. 

It is assumed that the reader has both working knowledge of all products involved, and the ability to perform the tasks outlined in this section. Administrators should have access to the product documentation for all products to install the required components.

The Archer IT Security Vulnerability Program use case must be installed and working prior to the integration. Perform the necessary tests to confirm that this is true before proceeding. 

The integration described in this guide is being provided as a reference implementation for evaluation and testing purposes.  It may or may not meet the needs and use cases for your organization.  If additional customizations or enhancements are needed, it is recommended that customers contact Archer Professional Services for assistance.

Important: In the event your integration is attempting to extract large amounts data, the execution of the JavaScript code could take multiple hours.  In order to avoid a timeout of the session token, the Archer Services Parameter must be extended. Currently the Archer Services account timeout parameter is set by default to 30 minutes.  In the event the JavaScript code has not completed in the allotted time-frame, the data feed will fail.

Schedule the data feeds

Important: A data feed must be active and valid to successfully run.

As you schedule your data feed, the Data Feed Manager validates the information. If any information is invalid, an error message displays. You can save the data feed and correct the errors later, but the data feed does not process until you make corrections.

Note: All IT Security Vulnerabilities Program data feeds are set to run daily by default.

  1. From the menu bar, click the  icon.

  2. Go to the Schedule tab of the data feed that you want to modify.

    1. From the menu bar, click the icon.

    2. Under Integration, click Data Feeds.

    3. Select the data feed.

    4. Click the Schedule tab.

  3. Go to the Recurrences section and complete frequency, start and stop times, and time zone.

  1. (Optional) To override the data feed schedule and immediately run your data feed, in the Run Data Feed Now section, click Start.

  2. Click Save.

Certification environment

Date Tested: February 2026

Product Name

Version Information

Operating System

Archer

2025.08

Virtual Appliance

Qualys Vulnerability Management (VM)

NA

NA