Import All

Import All

regscale import_all run takes a folder of scan export files, works out which scanner produced each file, and runs the matching RegScale importer for every file against a single System Security Plan (SSP). It is a convenient way to load a mixed batch of exports (for example a quarterly evidence drop containing Qualys, Nessus and Aqua files) without running a separate command per scanner.

Documented against CLI 6.49.8. This page describes what the command does today, including limitations. Where a limitation has a workaround, the workaround is listed next to it.

Overview

For one run, import_all:

  1. Optionally downloads scan files from S3 (see S3 downloads).
  2. Walks the folder recursively and collects every non-empty file, skipping the names and folders listed under Which files are picked up.
  3. Fingerprints each .csv, .json, .xml, .nessus and .xlsx file to identify the scanner (see How scanner detection works).
  4. Moves each recognised file into a subfolder named after its scanner, for example scans/qualys/.
  5. Asks whether you have custom mapping files, prints a per-scanner file count, and asks you to confirm.
  6. Runs each scanner's importer in turn against your SSP, pausing 5 seconds between scanners.

Your files are moved, not copied. After a run, files sit in <folder>/<scanner>/ instead of where you put them. Most importers then move each file they process into a processed/<date>/ folder, and import_all ignores any path containing processed on later runs, so an already-imported file is not normally imported twice. Keep originals elsewhere if you need them in place.

Prerequisites

  • RegScale CLI installed and logged in to your RegScale instance (regscale init, then regscale login). import_all uses the domain and token values in init.yaml, or the equivalent environment variables.
  • The numeric ID of the target SSP (visible in the RegScale URL for the plan).
  • Scan exports saved to a folder on the machine running the CLI.

import_all reads files only. It does not call the scanner vendors' APIs, so you do not need Qualys, Tenable, Wiz or other vendor credentials in init.yaml to use it.

Supported scanners

import_all can route to 16 scanner types. Ten work today. Six currently fail when run through import_all; for those, use the dedicated command or the workaround shown below.

Works through import_all

ScannerFile types acceptedDedicated command (same importer)
Aqua.csv, .xlsxregscale aqua import_aqua
AWS Inspector.csv, .jsonregscale aws inspector import_scans
Burp Suite.xmlregscale burp import_burp
AWS ECR.csv, .jsonregscale ecr import_ecr
IBM AppScan.csvregscale ibm import_appscan
Tenable Nessus.nessusregscale tenable nessus import_nessus
Rapid7 Nexpose.csvregscale nexpose import_nexpose
Prisma Cloud (compute CSV).csvregscale prisma import_prisma
Qualys.csv, .xlsxregscale qualys import_scans
JFrog Xray.jsonregscale xray import_xray

Notes:

  • Qualys exports are read with the importer's default --skip_rows 129, which expects the column headers on row 129 of the file (the value is the 1-based number of the header row). import_all cannot change this value. If your export has a different layout, use regscale qualys import_scans --skip_rows <n> directly.
  • Prisma here is the legacy compute CSV importer (import_prisma). Other Prisma commands (such as the regscale prisma sync_* commands) are not reachable through import_all.
  • Each importer expects its vendor's standard export columns (for example Nexpose needs Hostname, Vulnerability Title, Vulnerability ID). A file with different headers is not recognised, see Files that are not recognised.

Does not work through import_all

Microsoft Defender for Cloud (.csv) fails on every run, whether started from import_all or from regscale defender import_alerts. The importer passes dry_run, offset and limit to a constructor that does not accept them and stops with TypeError: Attributes.__new__() got an unexpected keyword argument 'dry_run'. There is no workaround in the current release; a CLI fix is needed.

The following importers attach data to either an SSP or a component, so they require --module and --parent_id instead of an SSP ID. import_all only supplies the SSP ID, so the run fails for these types with AttributeError: 'NoneType' object has no attribute 'lower'.

ScannerFile typesRun this instead
Grype.jsonregscale grype import_scans
OpenText WebInspect.xmlregscale opentext import_file
Snyk.json, .xlsxregscale snyk import_snyk
Trivy.jsonregscale trivy import_scans
Veracode.xml, .xlsx, .jsonregscale veracode import_veracode

Example, importing Snyk results into SSP 42:

regscale snyk import_snyk \
  --folder_path ./scans/snyk \
  --module securityplans \
  --parent_id 42

If a mixed folder contains these file types, move them out before running import_all (or accept that the run stops at the first one it reaches), then import them with the commands above.

Running it

regscale import_all run --folder_path ./scans --regscale_ssp_id 42

A typical session:

Do you have any custom mapping files? (y/n): n
qualys: 3 files
nessus: 2 files
aqua: 1 files
Do you want to proceed with processing 6 scan file(s)? (y/n): y

Answer y to the second prompt to start the imports. Any other answer prints Aborting scan processing. and exits, but note that files have already been moved into their scanner subfolders by that point.

If you omit --folder_path or --regscale_ssp_id, the CLI prompts for them.

Setting the scan date

--scan_date takes YYYY-MM-DD and is passed to every importer:

regscale import_all run -f ./scans -id 42 --scan_date 2026-09-30

Running unattended

import_all asks two yes/no questions with plain prompts, so a scheduler or container with no terminal will fail on them. Pipe the answers in (first answer: custom mappings, second: proceed):

printf 'n\ny\n' | regscale import_all run --folder_path /data/scans --regscale_ssp_id 42

This works only when every file in the folder is already recognised. An unrecognised file triggers a numbered scanner menu that needs a real answer, so for scheduled jobs, keep the folder to known exports or call the dedicated per-scanner commands directly.

Skipping the upload of source files

By default each importer also attaches the source file to the SSP. To turn that off:

regscale import_all run -f ./scans -id 42 --upload_file false

(Nessus does not attach files, so the flag has no effect for it.)

Options

OptionDescriptionDefault
--regscale_ssp_id, -idRequired. RegScale ID of the SSP that receives the data. Prompted for if omitted.none
--folder_path, -fFolder of scan files to process. Searched recursively. Prompted for if omitted.none
--scan_date, -sdScan date, YYYY-MM-DD.none
--upload_file, --uploadAttach each source file to the SSP after processing. Takes true or false.true
--mappings_path, -mAccepted, but ignored by import_all run. Each importer looks in ./mappings/<scanner>/ instead. See Custom column mappings../mappings/all
--disable_mapping, -dmAccepted, but ignored by import_all run. The custom-mapping question is always asked.off
--s3-bucket, --s3-prefix, --aws-profile, --aws_access_key_id, --aws_secret_access_key, --aws_session_tokenS3 download options. See S3 downloads.none

Which files are picked up

  • The folder is walked recursively, and zero-byte files are always skipped.
  • A file is skipped if its name contains any of: .DS_Store, ~, .zip, mapping.json, .md, .burp, .html. These are substring matches, so a file named q3~final.csv is skipped.
  • Any file whose full path contains processed is skipped. That includes everything inside a folder you named, for example, reprocessed-exports.
  • Only .csv, .json, .xml, .nessus and .xlsx files can be identified automatically. See the next section for every other extension.

How scanner detection works

import_all does not look at file names. It computes a fingerprint from the file's structure:

FormatWhat is hashed
.csv, .xlsxThe sorted column headers
.jsonThe key structure of the document
.xml, .nessusThe root element

The fingerprint is compared against a list that ships with the CLI. It holds 25 known fingerprints covering the 16 scanner types, so it recognises the standard exports from each tool but not every variant. A Qualys CSV with extra or renamed columns, for example, has a different fingerprint.

Files that are not recognised

When a file's fingerprint is not in the list, import_all prints a numbered menu and asks which scanner the file came from (option 1 skips the file):

1. SKIP FILE
2. aws
3. aqua
...
Enter the scan type number for file ./scans/custom-export.csv:

The answer is saved so the same format is recognised next time. Be aware of two limits in the current release:

  • Saving only works from a source checkout. The choice is written to a relative path inside the CLI source tree. When you run the installed CLI from any other directory, import_all fails with FileNotFoundError: ... scan_file_fingerprints.json immediately after you pick a scanner.
  • Files with an extension other than the five above are also sent to this menu, and a choice made for one of them is then applied to all such files.

Workaround for both: run the scanner's dedicated command (see the tables above) for any export import_all does not recognise.

Custom column mappings

Some importers can read exports whose columns have been renamed, using a mapping file. import_all asks:

Do you have any custom mapping files? (y/n):

If you answer y, it then asks per scanner for a mapping file path (Burp and Nessus are never asked, since they do not support custom mappings). If you answer n, or leave a scanner blank, each importer looks for mappings in ./mappings/<scanner>/ relative to where you run the command (for example ./mappings/qualys/).

--mappings_path and --disable_mapping on import_all run have no effect today. Use the per-scanner prompt, or place files in ./mappings/<scanner>/.

S3 downloads (currently not usable)

The command exposes --s3-bucket, --s3-prefix, --aws-profile and AWS key options, and its help describes them as an alternative to --folder_path. In the current release this mode cannot complete:

  • --s3-bucket and --folder_path are declared mutually exclusive, so passing both is rejected with 's3_bucket' is mutually exclusive with folder_path.
  • With only --s3-bucket, no local destination folder exists to download into, so nothing can be written.
  • Separately, --aws-profile is passed to the download in the wrong position, so a profile name is treated as an output file name.

Workaround: download the files first, then point --folder_path at them.

aws s3 sync s3://my-scan-bucket/exports/2026-09/ ./scans
regscale import_all run --folder_path ./scans --regscale_ssp_id 42

Troubleshooting

TypeError: Attributes.__new__() got an unexpected keyword argument 'dry_run'

The folder contained a Microsoft Defender file. Defender imports are currently broken (see above). Move the file out of the folder.

AttributeError: 'NoneType' object has no attribute 'lower'

The folder contained a Grype, OpenText, Snyk, Trivy or Veracode file. Those importers need --module and --parent_id. Move the files out and use the dedicated commands.

FileNotFoundError: ... scan_file_fingerprints.json

You picked a scanner for an unrecognised file while running the installed CLI. Use the scanner's dedicated command for that export.

A scanner's files were moved but nothing was imported

You answered n to the final prompt, or the run stopped on an error. The files are in <folder>/<scanner>/. Re-run import_all on the same folder (they are fingerprinted again) or run the dedicated command against that subfolder, for example regscale qualys import_scans --folder_path ./scans/qualys --regscale_ssp_id 42.

A file you expected was ignored

Check Which files are picked up: the name contains one of the excluded substrings, the path contains processed, or the file is empty.

EOFError when running from a scheduler

A prompt had no input. Pipe in the answers as shown in Running unattended, and make sure every file in the folder is a recognised export.

The run aborts with a parse error before any prompt

Fingerprinting reads every .csv, .json, .xml, .nessus and .xlsx file, and a malformed or header-less file stops the whole run. Remove or repair the file and run again.


Did this page help you?