Create AWS Connectors (2024)

Go to the Connectors tab, click Amazon Web Services Connectors, and then click Create Connector, and our wizard can walk you through the steps.

Step 1:Basic DetailsBasic Details

Provide a name and description for the connector. We recommendyou provide a unique name for the connector.

Select applications that are applicable for the connector.

Select Enable Remediation to enable remediation on the connector. You need to configure additional permissions before you enable remediation for AWS connectors.

Note: Ensure that the connector has write access tothe AWS account for which you enable remediation.Refer to Configuring Remediation for AWS.

Create AWS Connectors (1)

Step 2: Authentication DetailsAuthentication Details

Account Type

Select an account type for your connector: Global, US GovCloud, or China. You can choose only one account type per connector.

Create AWS Connectors (2)

Polling Frequency

Select a frequency at which the connector should poll the cloud provider and fetch data.

By default, the connector polling frequency is configured for every 4 hours. As a result, the connector connects with the cloud provider every 4 hours to fetch the data.

You can configure frequency from one hour to a maximum of 24 hours. We recommend configuring a frequency of 4 hours or more for optimal use of your connector. Configuring a low polling frequency (less than 4 hours) can affect the connector's performance and may result in AWS API throttling error.

Cross-account ARN

This lets you grant Qualys access to your AWS resources without sharing your AWS security credentials. Qualys accesses your AWS resources by assuming the IAM role you create in your AWS account.Learn more.

AWS requires that vendors provide a unique external ID value amongst all their customers when providing a vendor account for a trust relationship. However, we no longer require customers to adhere to any fixed format for external IDs.Learn more

You must provide an external ID to download a valid template while creating a role using CloudFormation.

In the Application list, select TotalCloud/AssetView,paste Role ARN, and click Add.

Create AWS Connectors (3)

Test Connection

Click Test Connectionto verify if the connector can successfully authenticate using the provided role ARN information. If the test connection is successful, proceed with the connector creation process. If the test connection fails, you may need to check and update the authentication details.

Step 3: Region SelectionRegion Selection

Select regions to discover the asset/resource and fetch the data from all the selected regions.

Note:Region selection is only applicable for AV connectors. CSPM connectors will continue to show resources for all the regions even if a few regions are selected while creating connectors.

Create AWS Connectors (4)

Step 4: Tags and ActivationTags and Activation

We can activate AWS assets for scanning automatically, so you do nothave to take this extra step. Select the required check box to enable activation for the required app. We automatically activate the assets as they are discovered and even assign them tags if you want.

Enabling Cloud Perimeter Scan

When you select theAutomatically activate all assets for VM Scanning application check box, you can see a check box to enable cloud perimeter scan.

Create AWS Connectors (5)

Select the Enable Cloud Perimeter Scan if you want to enable launching perimeter scans on your EC2 assets.

Perimeter scan jobsare run automatically based on the settings defined in the Scan Settings step or in theCloud Perimeter Scan - Global Scan Configuration.

Enabling Zero-touch API Based Scan

When you select theAutomatically activate all assets for VM Scanning application check box, a check box to enable zero-touch API based scan becomes visible.

Create AWS Connectors (6)

Select the Enable Zero-touch API based Scan if you want to utilize cloud native API to perform real-time vulnerability assessments on new EC2 instances.

The API scan captures events from your AWS environment in real-time to identify new instances in the cloud inventory. To allow Qualys to listen to events in your AWS account for API scanning, refer toConfigure Zero-touch API-based Assessment.

Select Asset Tags

We recommend you create at least one generic asset tag (for example, EC2) and have the connector automatically apply that tag to all imported assets. You can add more tags to your EC2 assets based upon discovered EC2 metadata.

Step 5: Scan SettingsScan Settings

The step for defining scan settings is available only if you selectthe Enable Cloud Perimeter Scan check box in the Tags and Activation step.

In this step, you can define customized settings for cloud perimeter scans for the specific connector that you are creating.

If you do not define the custom scan configuration for the connector, the global scan configuration is used for launching the cloud perimeter scan. For details on global scan configuration, seeCloud Perimeter Scan - Global Scan Configuration.

Select the Enable custom scan configuration check box. You can define scan settings, such asscan prefix, option profile, recurrence, and timezone.

For details of the scan settings fields, seeCloud Perimeter Scan - Global Scan Configuration.

Step 6: Assign TagsAssign Tags

Assign tags to the connector that you are creating.You can also create a new tag. For details on creating new tags, see Configure Tags inQualys CyberSecurity Asset Management documentation.

Step 7: ConfirmationConfirmation

Review the connector settings you configured and then click Create Connector.

That’s it! The connector establishes a connection with Amazon Web Services to start discovering resources from configured region.

Once the connector is created, you can run the connector, disable or delete the connector, andview assets and resources information.

TheAmazon Web Services page displays thelist of AWS connectors. The Status column indicates the status of the connector created: Completed successfully, Completed with errors, Queued, Synchronizing, and Disabled.

Frequently Asked Questions

What if my EC2 instances have IP address changes?What if my EC2 instances have IP address changes?

Your EC2 instances may have IP address changes. We can continue to scan your EC2 instances because we scan by EC2 instance ID (not by IP address). If changes are found by an EC2 scan, you can see the new IP addresses in your scan results. Once these scan results are processed the new IP addresses are shown in your account and is included in your scan reports.

AWSAssets: Status and BehaviorAWSAssets: Status and Behavior

The AWS assets are detected by EC2 connector and/or Cloud Agent. The status in asset records from the EC2 connector is updated with every connector run. However, if an asset in terminated, only the asset records from EC2 connector reflects the terminated status after connector run.

The asset records from Cloud Agent running in AWS and instances from EC2 connector are automatically merged into a single asset record and it correctly reflects the status. The asset records from Cloud Agent, which are not merged with record fetched via connector does not reflect the terminated status.

Create AWS Connectors (2024)

FAQs

How do I create an AWS connector? ›

To create a connector using the console

Sign in to your AWS account and open the AWS Private CA Connector for Active Directory console at https://console.aws.amazon.com/pca-connector-ad/home . On the first-time service landing page or the Connectors for Active Directory page, choose Create connector.

What is an AWS connector? ›

AWS Service Management Connector and its integration connectors enable you to provision, manage, and operate native AWS resources and capabilities in familiar IT Service Management (ITSM) tooling, such as ServiceNow and Atlassian.

What is AWS SMC? ›

AWS Service Management Connector (SMC) enables users to provision, manage, and operate AWS resources and capabilities in familiar IT Service Management (ITSM) tooling (for example, ServiceNow and Atlassian). These integrations enable organizations to migrate and adopt AWS faster and at-scale.

How do I create an AWS ad connector? ›

Create an AD Connector
  1. In the AWS Directory Service console navigation pane, choose Directories and then choose Set up directory.
  2. On the Select directory type page, choose AD Connector, and then choose Next.
  3. On the Enter AD Connector information page, provide the following information:

How do I create a VPC connector? ›

You can associate your service with a VPC by creating a VPC endpoint from the App Runner console, called VPC Connector. To create a VPC Connector, specify the VPC, one or more subnets, and optionally one or more security groups. After you configure a VPC Connector, you can use it with one or more App Runner services.

What is AWS glue service? ›

AWS Glue is a serverless data integration service that makes data preparation simpler, faster, and cheaper. You can discover and connect to over 70 diverse data sources, manage your data in a centralized data catalog, and visually create, run, and monitor ETL pipelines to load data into your data lakes.

What is SOCS in AWS? ›

AWS System and Organization Controls (SOC) Reports are independent third-party examination reports that demonstrate how AWS achieves key compliance controls and objectives. The purpose of these reports is to help you and your auditors understand the AWS controls established to support operations and compliance.

What is SMC in server? ›

Server Management Control is a set of interrelated client/server software applications for SAIL-based systems that provides system control capabilities such as OS 2200 partitioning, initialization, and booting. This includes configuration of consoles and console recovery.

How do I create a service connector? ›

Create the service connector by importing a WSDL file. After you import the WSDL file, you need to perform minor manual tasks to complete the service connector. After you create the service connector, you must configure a connection to be able to use the service connector in a process.

How to create API connector? ›

  1. Set Up Ingestion API Connector. Schema File Requirements.
  2. Create an Ingestion API Data Stream.
  3. Create a Connected App.
  4. Find Connector Status for Ingestion API.
  5. Share Ingestion API Developer Information.
  6. Delete Ingestion API Connector.

How do I create a service connection with AWS? ›

To set up a service connection

From New AWS service connection, choose AWS. This opens the Add AWS service connection form. Provide a Connection name, Access key ID, and Secret key ID, and complete any other fields you want. When you've completed the required and any optional fields in the form, choose OK.

Top Articles
Ready-Made Clone Apps Detailed Guide
Differences Between Obfuscation and Encryption - Blue Goat Cyber
Rosy Boa Snake — Turtle Bay
Ffxiv Act Plugin
Golden Abyss - Chapter 5 - Lunar_Angel
Celebrity Extra
Costco The Dalles Or
His Lost Lycan Luna Chapter 5
My Vidant Chart
Boat Jumping Female Otezla Commercial Actress
Whitley County Ky Mugshots Busted
General Info for Parents
Discover Westchester's Top Towns — And What Makes Them So Unique
Mary Kay Lipstick Conversion Chart PDF Form - FormsPal
Bahsid Mclean Uncensored Photo
Fool’s Paradise movie review (2023) | Roger Ebert
Find Such That The Following Matrix Is Singular.
Icommerce Agent
How To Cancel Goodnotes Subscription
V-Pay: Sicherheit, Kosten und Alternativen - BankingGeek
How your diet could help combat climate change in 2019 | CNN
Vegas7Games.com
Joan M. Wallace - Baker Swan Funeral Home
Great Clips Grandview Station Marion Reviews
2021 Volleyball Roster
Okc Body Rub
Dewalt vs Milwaukee: Comparing Top Power Tool Brands - EXTOL
Engineering Beauties Chapter 1
14 Top-Rated Attractions & Things to Do in Medford, OR
Tripcheck Oregon Map
Wega Kit Filtros Fiat Cronos Argo 1.8 E-torq + Aceite 5w30 5l
Royal Caribbean Luggage Tags Pending
The Pretty Kitty Tanglewood
Ark Unlock All Skins Command
Synchrony Manage Account
The 50 Best Albums of 2023
Elizaveta Viktorovna Bout
Sam's Club Gas Prices Florence Sc
Engr 2300 Osu
Pike County Buy Sale And Trade
Sound Of Freedom Showtimes Near Amc Mountainside 10
Lady Nagant Funko Pop
Mybiglots Net Associates
Csgold Uva
Wgu Admissions Login
3500 Orchard Place
Hillsborough County Florida Recorder Of Deeds
Enter The Gungeon Gunther
Myapps Tesla Ultipro Sign In
18 Seriously Good Camping Meals (healthy, easy, minimal prep! )
Frank 26 Forum
Latest Posts
Article information

Author: Rob Wisoky

Last Updated:

Views: 5864

Rating: 4.8 / 5 (48 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Rob Wisoky

Birthday: 1994-09-30

Address: 5789 Michel Vista, West Domenic, OR 80464-9452

Phone: +97313824072371

Job: Education Orchestrator

Hobby: Lockpicking, Crocheting, Baton twirling, Video gaming, Jogging, Whittling, Model building

Introduction: My name is Rob Wisoky, I am a smiling, helpful, encouraging, zealous, energetic, faithful, fantastic person who loves writing and wants to share my knowledge and understanding with you.