elastic / elastic/integrations
[qualys_gav]: Retention enabled by default and not configurable
- Dominant language
- Handlebars
- Stars
- 333
- Forks
- 647
- Avg merge
- 3d 4h
- Merged PRs (30d)
- 209
Description
### Integration Name
Qualys Global AssetView [qualys_gav]
### Dataset Name
qualys_gav.asset
### Integration Version
0.1.0
### Agent Version
9.1.0
### Agent Output Type
elasticsearch
### Elasticsearch Version
9.1.0
### OS Version and Architecture
elastic-package
### Software/API Version
2.0
### Error Message
No error message
### Event Original
N/A
### What did you do?
I configured the Qualys GAV application through the UI.
### What did you see?
I've seen than an ILM is configured on the `qualys_gav.asset` datastream. It doesn't seem to be configurable, nor we have the possibility to disable it.
### What did you expect to see?
I would expect those solutions, in this prefered order:
- ILM is configurable in the UI: enable/disable and possibility to select the retention period
- Configurable through a standalone yaml config file
- Disabled by default if not configurable
- Removed
### Anything else?
One of the reason we asked to have the Qualys Global AssetView elastic agent integration is the possibility to build trends. If an ILM is configured with a 30 days retention, we loose the interest.
Contributor guide
Assessment
This issue has not been assessed yet.