What Changed
QualysVM connector updated to include API rate limiting (1 QPS) and configurable truncation limits (20-5000 range) to prevent customer incidents where excessive API calls impacted performance.
Security Impact (Visibility & Fidelity)
Prevents service degradation from API abuse scenarios where truncation_limit=1 caused one host per API call, generating excessive API requests. Rate limiting protects both customer and Qualys infrastructure while maintaining data collection reliability.
Affected Files
Solutions/QualysVM/Data Connectors/QualysVMHostLogs_ccp/QualysVMHostLogs_ConnectorDefinition.json
Solutions/QualysVM/Data Connectors/QualysVMHostLogs_ccp/QualysVMHostLogs_PollingConfig.json
(packaging artefacts: 3.0.7.zip, mainTemplate.json, createUiDefinition.json, ReleaseNotes.md, SolutionMetadata.json, Solution_QualysVM.json)
(.github/workflows/ScanSecrets.yaml, Tools/Create-Azure-Sentinel-Solution/common/createCCPConnector.ps1)