> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Scanning Linux

> Capturing Linux systems over SSH—as root, as a user with sudo, or with a private key.

The *Linux* scan module signs in to the system over SSH and reads it out. It
can sign in as `root`, as a user with `sudo`, or with a private key. It
requires a connected [gateway](/docs/en/scan/gateway-install).

## Captured data

Each system becomes an asset of the type *Linux*. The detail page groups the
data as follows:

| Group | Content |
| - | - |
| Linux | software, local users and groups, cron, daemons, network services, partitions, network connections, routing, NFS exports |
| Kernel | modules, parameters, CPU patch |
| System Components | BIOS and baseboard, CPU, memory, mass storage, optical drives, display, audio, network adapters, SCSI, platform security |
| Docker | containers, images, networks, volumes, disk usage, Compose stacks, components |

How the detail page of the type is structured is described in
[Systems](/docs/en/assets/systems).

## Setting up the job

The wizard follows the standard path *Basics* › *Targets* › *Schedule* ›
*Summary*—see [Creating a Scan Job](/docs/en/scan/create-inventory). The
*Targets* step is what sets this module apart.

Each row carries four columns:

| Column | Content |
| - | - |
| *IP/Hostname* | an address, a range, a network in CIDR notation (e.g. /24) or a hostname |
| *Credentials* | an entry of the type *SSH Access* |
| *Port* | the target's SSH port, prefilled with 22 |
| *Sudo* | set when the scan signs in as a user with `sudo` |

An entry of the type *SSH Access* carries *Username* and *Method*: with
*Password* or with *Private Key*, and with a private key optionally a
*Passphrase*. An entry in *Credentials for all targets* applies to every row
without an assignment of its own.

## Prerequisites

### Ports and protocols

| Protocol | Port | Transport |
| - | - | - |
| SSH, including SFTP over it | 22 | TCP |

If a system uses a different SSH port, enter it in the *Port* column.

### Permissions

The account matches one of these three variants:

| Variant | Requirement |
| - | - |
| `root` | Signing in as `root` over SSH is allowed. Only with `root` is the scan complete without a `sudo` configuration. |
| User with `sudo` | The user is authorized through the `sudo` configuration for exactly the commands the scan runs as `root`; the `gensudo.sh` script generates the line for it. *Sudo* is set in the target row. The user has a login shell. |
| Private key | The key is in OpenSSH format. The public key is in the user's `~/.ssh/authorized_keys` on the system, on a line of its own; directory and file can differ by distribution. |

Supported key types: `ecdsa-sha2-nistp256`, `ecdsa-sha2-nistp384`,
`ecdsa-sha2-nistp521`, `ssh-ed25519` and `ssh-rsa`.

<Warning>
  A user with `sudo` but without a login shell returns an incomplete scan, even
  though the `sudo` configuration is correct. Create the user with `adduser`;
  the user then gets a login shell automatically.
</Warning>

How you run `gensudo.sh` and add its line to the `sudoers` file is in
[Scanning by Script](/docs/en/scan/scan-by-script#linux).

### Network requirements

* SSH is enabled on the Linux system.
* The firewall allows the port.
* The distribution is supported.

If SSH is not available, or neither `root` nor `sudo` can be set up, scan the
system with the `Discovery-Linux` (64-bit) or `Discovery-Linux-Legacy` (32-bit)
scan script—see [Scanning by Script](/docs/en/scan/scan-by-script#linux). The script
also suits IGEL thin clients running Linux; they then appear as a Linux system,
not as a thin client.

## Common issues

| Symptom | Cause | Resolution |
| - | - | - |
| The scan succeeds but returns only part of the information. | The account is neither `root` nor a user with a `sudo` configuration. | Scan as `root` or set up `sudo`. |
| Data is missing despite the `sudo` configuration. | The user has no login shell. | Assign a login shell, or create the user with `adduser`. |

## Related

After it is created, the job appears among the jobs; how you watch and adjust
it is in [Managing Jobs](/docs/en/scan/manage-jobs). You capture Macs with
[macOS](/docs/en/scan/macos).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.