QQL Search Token Standardization Notification

Sachin Kesarkar

We have implemented Qualys Query Language (QQL) token standardization across all Qualys Modules. This update introduces a unified naming convention for both common and TotalCloud KCS (Kubernetes and container security) specific tokens, improving consistency and usability.

As part of this enhancement, both common and TotalCloud KCS Security-specific tokens are updated with new token names that follow a standard, consistent nomenclature.

Key Enhancements

  • Standardized Token Naming: Tokens now follow the structured format of syntax: entity.attribute[.subattribute…]

    For example, in the new token, container.image.qdsSeverity, container is the entity, image is the attribute, and qdsSeverity is a sub-attribute.

In container.k8s.resourcePostures.criticality, container is the entity, k8s is the attribute, and resourcePostures.criticality is a sub-attribute.

  • Search Bar Updates: Only the new tokens are displayed in the auto-suggestion in the search bars within the UI. However, if you type the old token name manually, the QQL query still works. The old tokens will not be visible in the auto-suggestions on the UI. 
  • Backward Compatibility: Existing Dashboard widgets and Saved Search Queries continue to support old tokens in edit mode, ensuring no disruption to current workflows. 
  • Improved Interoperability: This update streamlines QQL queries, enhances interoperability across all Qualys products, and ensures a smoother user experience while maintaining backward compatibility for existing configurations.

What’s Next

For more information, please refer to TotalCloud KCS 1.41 release notes. If you have any questions, please contact Qualys Support.

Share your Comments

Comments

Your email address will not be published. Required fields are marked *