Import All
Import All
regscale import_all run takes a folder of scan export files, works out which scanner produced each file, and runs the matching RegScale importer for every file against a single System Security Plan (SSP). It is a convenient way to load a mixed batch of exports (for example a quarterly evidence drop containing Qualys, Nessus and Aqua files) without running a separate command per scanner.
Documented against CLI 6.49.8. This page describes what the command does today, including limitations. Where a limitation has a workaround, the workaround is listed next to it.
Overview
For one run, import_all:
- Optionally downloads scan files from S3 (see S3 downloads).
- Walks the folder recursively and collects every non-empty file, skipping the names and folders listed under Which files are picked up.
- Fingerprints each
.csv,.json,.xml,.nessusand.xlsxfile to identify the scanner (see How scanner detection works). - Moves each recognised file into a subfolder named after its scanner, for example
scans/qualys/. - Asks whether you have custom mapping files, prints a per-scanner file count, and asks you to confirm.
- Runs each scanner's importer in turn against your SSP, pausing 5 seconds between scanners.
Your files are moved, not copied. After a run, files sit in
<folder>/<scanner>/instead of where you put them. Most importers then move each file they process into aprocessed/<date>/folder, andimport_allignores any path containingprocessedon later runs, so an already-imported file is not normally imported twice. Keep originals elsewhere if you need them in place.
Prerequisites
- RegScale CLI installed and logged in to your RegScale instance (
regscale init, thenregscale login).import_alluses thedomainandtokenvalues ininit.yaml, or the equivalent environment variables. - The numeric ID of the target SSP (visible in the RegScale URL for the plan).
- Scan exports saved to a folder on the machine running the CLI.
import_all reads files only. It does not call the scanner vendors' APIs, so you do not need Qualys, Tenable, Wiz or other vendor credentials in init.yaml to use it.
Supported scanners
import_all can route to 16 scanner types. Ten work today. Six currently fail when run through import_all; for those, use the dedicated command or the workaround shown below.
Works through import_all
import_all| Scanner | File types accepted | Dedicated command (same importer) |
|---|---|---|
| Aqua | .csv, .xlsx | regscale aqua import_aqua |
| AWS Inspector | .csv, .json | regscale aws inspector import_scans |
| Burp Suite | .xml | regscale burp import_burp |
| AWS ECR | .csv, .json | regscale ecr import_ecr |
| IBM AppScan | .csv | regscale ibm import_appscan |
| Tenable Nessus | .nessus | regscale tenable nessus import_nessus |
| Rapid7 Nexpose | .csv | regscale nexpose import_nexpose |
| Prisma Cloud (compute CSV) | .csv | regscale prisma import_prisma |
| Qualys | .csv, .xlsx | regscale qualys import_scans |
| JFrog Xray | .json | regscale xray import_xray |
Notes:
- Qualys exports are read with the importer's default
--skip_rows 129, which expects the column headers on row 129 of the file (the value is the 1-based number of the header row).import_allcannot change this value. If your export has a different layout, useregscale qualys import_scans --skip_rows <n>directly. - Prisma here is the legacy compute CSV importer (
import_prisma). Other Prisma commands (such as theregscale prisma sync_*commands) are not reachable throughimport_all. - Each importer expects its vendor's standard export columns (for example Nexpose needs
Hostname,Vulnerability Title,Vulnerability ID). A file with different headers is not recognised, see Files that are not recognised.
Does not work through import_all
import_allMicrosoft Defender for Cloud (.csv) fails on every run, whether started from import_all or from regscale defender import_alerts. The importer passes dry_run, offset and limit to a constructor that does not accept them and stops with TypeError: Attributes.__new__() got an unexpected keyword argument 'dry_run'. There is no workaround in the current release; a CLI fix is needed.
The following importers attach data to either an SSP or a component, so they require --module and --parent_id instead of an SSP ID. import_all only supplies the SSP ID, so the run fails for these types with AttributeError: 'NoneType' object has no attribute 'lower'.
| Scanner | File types | Run this instead |
|---|---|---|
| Grype | .json | regscale grype import_scans |
| OpenText WebInspect | .xml | regscale opentext import_file |
| Snyk | .json, .xlsx | regscale snyk import_snyk |
| Trivy | .json | regscale trivy import_scans |
| Veracode | .xml, .xlsx, .json | regscale veracode import_veracode |
Example, importing Snyk results into SSP 42:
regscale snyk import_snyk \
--folder_path ./scans/snyk \
--module securityplans \
--parent_id 42
If a mixed folder contains these file types, move them out before running import_all (or accept that the run stops at the first one it reaches), then import them with the commands above.
Running it
regscale import_all run --folder_path ./scans --regscale_ssp_id 42
A typical session:
Do you have any custom mapping files? (y/n): n
qualys: 3 files
nessus: 2 files
aqua: 1 files
Do you want to proceed with processing 6 scan file(s)? (y/n): y
Answer y to the second prompt to start the imports. Any other answer prints Aborting scan processing. and exits, but note that files have already been moved into their scanner subfolders by that point.
If you omit --folder_path or --regscale_ssp_id, the CLI prompts for them.
Setting the scan date
--scan_date takes YYYY-MM-DD and is passed to every importer:
regscale import_all run -f ./scans -id 42 --scan_date 2026-09-30
Running unattended
import_all asks two yes/no questions with plain prompts, so a scheduler or container with no terminal will fail on them. Pipe the answers in (first answer: custom mappings, second: proceed):
printf 'n\ny\n' | regscale import_all run --folder_path /data/scans --regscale_ssp_id 42
This works only when every file in the folder is already recognised. An unrecognised file triggers a numbered scanner menu that needs a real answer, so for scheduled jobs, keep the folder to known exports or call the dedicated per-scanner commands directly.
Skipping the upload of source files
By default each importer also attaches the source file to the SSP. To turn that off:
regscale import_all run -f ./scans -id 42 --upload_file false
(Nessus does not attach files, so the flag has no effect for it.)
Options
| Option | Description | Default |
|---|---|---|
--regscale_ssp_id, -id | Required. RegScale ID of the SSP that receives the data. Prompted for if omitted. | none |
--folder_path, -f | Folder of scan files to process. Searched recursively. Prompted for if omitted. | none |
--scan_date, -sd | Scan date, YYYY-MM-DD. | none |
--upload_file, --upload | Attach each source file to the SSP after processing. Takes true or false. | true |
--mappings_path, -m | Accepted, but ignored by import_all run. Each importer looks in ./mappings/<scanner>/ instead. See Custom column mappings. | ./mappings/all |
--disable_mapping, -dm | Accepted, but ignored by import_all run. The custom-mapping question is always asked. | off |
--s3-bucket, --s3-prefix, --aws-profile, --aws_access_key_id, --aws_secret_access_key, --aws_session_token | S3 download options. See S3 downloads. | none |
Which files are picked up
- The folder is walked recursively, and zero-byte files are always skipped.
- A file is skipped if its name contains any of:
.DS_Store,~,.zip,mapping.json,.md,.burp,.html. These are substring matches, so a file namedq3~final.csvis skipped. - Any file whose full path contains
processedis skipped. That includes everything inside a folder you named, for example,reprocessed-exports. - Only
.csv,.json,.xml,.nessusand.xlsxfiles can be identified automatically. See the next section for every other extension.
How scanner detection works
import_all does not look at file names. It computes a fingerprint from the file's structure:
| Format | What is hashed |
|---|---|
.csv, .xlsx | The sorted column headers |
.json | The key structure of the document |
.xml, .nessus | The root element |
The fingerprint is compared against a list that ships with the CLI. It holds 25 known fingerprints covering the 16 scanner types, so it recognises the standard exports from each tool but not every variant. A Qualys CSV with extra or renamed columns, for example, has a different fingerprint.
Files that are not recognised
When a file's fingerprint is not in the list, import_all prints a numbered menu and asks which scanner the file came from (option 1 skips the file):
1. SKIP FILE
2. aws
3. aqua
...
Enter the scan type number for file ./scans/custom-export.csv:
The answer is saved so the same format is recognised next time. Be aware of two limits in the current release:
- Saving only works from a source checkout. The choice is written to a relative path inside the CLI source tree. When you run the installed CLI from any other directory,
import_allfails withFileNotFoundError: ... scan_file_fingerprints.jsonimmediately after you pick a scanner. - Files with an extension other than the five above are also sent to this menu, and a choice made for one of them is then applied to all such files.
Workaround for both: run the scanner's dedicated command (see the tables above) for any export import_all does not recognise.
Custom column mappings
Some importers can read exports whose columns have been renamed, using a mapping file. import_all asks:
Do you have any custom mapping files? (y/n):
If you answer y, it then asks per scanner for a mapping file path (Burp and Nessus are never asked, since they do not support custom mappings). If you answer n, or leave a scanner blank, each importer looks for mappings in ./mappings/<scanner>/ relative to where you run the command (for example ./mappings/qualys/).
--mappings_path and --disable_mapping on import_all run have no effect today. Use the per-scanner prompt, or place files in ./mappings/<scanner>/.
S3 downloads (currently not usable)
The command exposes --s3-bucket, --s3-prefix, --aws-profile and AWS key options, and its help describes them as an alternative to --folder_path. In the current release this mode cannot complete:
--s3-bucketand--folder_pathare declared mutually exclusive, so passing both is rejected with's3_bucket' is mutually exclusive with folder_path.- With only
--s3-bucket, no local destination folder exists to download into, so nothing can be written. - Separately,
--aws-profileis passed to the download in the wrong position, so a profile name is treated as an output file name.
Workaround: download the files first, then point --folder_path at them.
aws s3 sync s3://my-scan-bucket/exports/2026-09/ ./scans
regscale import_all run --folder_path ./scans --regscale_ssp_id 42
Troubleshooting
TypeError: Attributes.__new__() got an unexpected keyword argument 'dry_run'
TypeError: Attributes.__new__() got an unexpected keyword argument 'dry_run'The folder contained a Microsoft Defender file. Defender imports are currently broken (see above). Move the file out of the folder.
AttributeError: 'NoneType' object has no attribute 'lower'
AttributeError: 'NoneType' object has no attribute 'lower'The folder contained a Grype, OpenText, Snyk, Trivy or Veracode file. Those importers need --module and --parent_id. Move the files out and use the dedicated commands.
FileNotFoundError: ... scan_file_fingerprints.json
FileNotFoundError: ... scan_file_fingerprints.jsonYou picked a scanner for an unrecognised file while running the installed CLI. Use the scanner's dedicated command for that export.
A scanner's files were moved but nothing was imported
You answered n to the final prompt, or the run stopped on an error. The files are in <folder>/<scanner>/. Re-run import_all on the same folder (they are fingerprinted again) or run the dedicated command against that subfolder, for example regscale qualys import_scans --folder_path ./scans/qualys --regscale_ssp_id 42.
A file you expected was ignored
Check Which files are picked up: the name contains one of the excluded substrings, the path contains processed, or the file is empty.
EOFError when running from a scheduler
EOFError when running from a schedulerA prompt had no input. Pipe in the answers as shown in Running unattended, and make sure every file in the folder is a recognised export.
The run aborts with a parse error before any prompt
Fingerprinting reads every .csv, .json, .xml, .nessus and .xlsx file, and a malformed or header-less file stops the whole run. Remove or repair the file and run again.
Updated about 5 hours ago
