What Changed

QualysVM connector updated to include API rate limiting (1 QPS) and configurable truncation limits (20-5000 range) to prevent customer incidents where excessive API calls impacted performance.

Security Impact (Visibility & Fidelity)

Prevents service degradation from API abuse scenarios where truncation_limit=1 caused one host per API call, generating excessive API requests. Rate limiting protects both customer and Qualys infrastructure while maintaining data collection reliability.

Affected Files

Solutions/QualysVM/Data Connectors/QualysVMHostLogs_ccp/QualysVMHostLogs_ConnectorDefinition.json
Solutions/QualysVM/Data Connectors/QualysVMHostLogs_ccp/QualysVMHostLogs_PollingConfig.json
(packaging artefacts: 3.0.7.zip, mainTemplate.json, createUiDefinition.json, ReleaseNotes.md, SolutionMetadata.json, Solution_QualysVM.json)
(.github/workflows/ScanSecrets.yaml, Tools/Create-Azure-Sentinel-Solution/common/createCCPConnector.ps1)