elastic / elastic/integrations

[qualys_gav]: Retention enabled by default and not configurable

Open
#15,164 3 comments 0 reactions 1 assignee Claimed by @ShourieG View on GitHub
Integration:qualys_gav needs:triage Team:Security-Service Integrations
Dominant language
Handlebars
Stars
333
Forks
647
Avg merge
3d 4h
Merged PRs (30d)
209

Description

### Integration Name

Qualys Global AssetView [qualys_gav]

### Dataset Name

qualys_gav.asset

### Integration Version

0.1.0

### Agent Version

9.1.0

### Agent Output Type

elasticsearch

### Elasticsearch Version

9.1.0

### OS Version and Architecture

elastic-package

### Software/API Version

2.0

### Error Message

No error message

### Event Original

N/A

### What did you do?

I configured the Qualys GAV application through the UI.

### What did you see?

I've seen than an ILM is configured on the `qualys_gav.asset` datastream. It doesn't seem to be configurable, nor we have the possibility to disable it.

### What did you expect to see?

I would expect those solutions, in this prefered order:
- ILM is configurable in the UI: enable/disable and possibility to select the retention period
- Configurable through a standalone yaml config file
- Disabled by default if not configurable
- Removed

### Anything else?

One of the reason we asked to have the Qualys Global AssetView elastic agent integration is the possibility to build trends. If an ILM is configured with a 30 days retention, we loose the interest.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.