> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Scan Reference

> Credential types, target entries, module settings, status values, fixed sizes and terms for looking up.

## The scan modules

The catalog shows 27 modules. *Basics*, *Schedule* and *Summary* are the same for
all; only the middle part differs. Which modules there are, which of them have a
guide of their own and which steps and target columns the rest carry is in
[Scan Modules – Overview](/docs/en/scan/scan-modules).

The step with the targets is called *Targets* with every module that carries a
target list. One row is one scan target; above it stands the
*Credentials for all targets* field with an optional override per row.

The *Credentials* column carries the same name with every module, even where no
account stands in it: with *SNMP v1 and v2* a community is held in it.

With five modules the column may stay empty, because the scan can run under the
gateway's service account: *Windows DNS*, *Windows DHCP*, *DFS*,
*Microsoft SQL Server* and *Hyper-V*.

### What may go into the target column

| Accepted input | Modules |
| - | - |
| IP, CIDR (e.g. /24), range or hostname | standard |
| IP, CIDR (e.g. /24) or hostname | *Windows DNS*, *Windows DHCP*, *DFS*, *Veeam B\&R* |
| MSSQL server name or instance name | *Microsoft SQL Server* |
| Cluster address or name | *Nutanix* |
| HTTP endpoint or storage name | *Storage* |

## Credential types

| Type | Intended for | Fields besides the name |
| - | - | - |
| *User Account* | Windows, VMware, Nutanix, Proxmox and others | *Username*, *Password* |
| *SSH Access* | Linux and macOS | *Username*, *Method* (*Password* or *Private Key*), *Password*, *Private Key*, *Passphrase* |
| *SNMP v1 and v2* | devices with a community | *Community* |
| *SNMPv3* | devices with a user account and encryption | *Username*, *Authentication Algorithm*, *Authentication Password*, *Encryption Algorithm*, *Encryption Password*, *Context Name* |
| *API Key* | Cisco Meraki | a single masked key field |
| *Entra ID App* | Microsoft 365, Microsoft Intune | *Display Name*, *Primary Domain or Tenant ID*, *Application ID*, plus *Client Secret* or *Certificate (.pfx)* with *Certificate Password*, plus *Expiration Date* |
| *AWS Access Key* | AWS | *Access Key ID*, *Secret Access Key* |

SNMPv3 algorithms: authentication *None*, *MD5*, *SHA-1* · encryption *None*,
*AES*, *AES-128*, *AES-192*, *AES-256*, *DES*, *TDES*. If the authentication
stands at *None*, the encryption jumps to *None* with it.

Storage mode per entry: *Reusable* (permanently in the vault) or *One-time* (for
this job only, not saved).

The list under *Scan › Credentials* carries five columns: *Name*, *Type*,
*Username*, *Expiration Date* and *Storage Location* (*Vault* or *Gateway*).

## Windows components

*Windows (AD)* and *Windows (IP)* collect 22 components; 20 are preselected. The
complete table is on the module page
[Windows](/docs/en/scan/windows#windows-components).

## Module settings

In the middle part of the wizard behind the *Customize* button:

| Module | Setting | Default |
| - | - | - |
| *Active Directory* | *Do Not Collect Personal Data* | off |
| *Active Directory* | *Do Not Collect Extended Attributes* | off |
| *Windows (AD)*, *Windows (IP)* | *Windows Components* | 20 of 22 |
| *Microsoft SQL Server* | *Collect System Databases* | off |
| *Veeam B\&R* | *Collect Backup History (Days)* | 42 |

All other modules do not show the button.

### Bounds of the number fields

A value outside these bounds is pulled to the bound without a message when you
leave the field.

| Field | Range |
| - | - |
| *Collect Backup History (Days)* | 0 to 3650 |
| *Timeout (ms)* with *SNMP v1 and v2* and *SNMPv3* | 100 to 60000 |
| *Port* with *Linux*, *macOS*, *MySQL Server*, *Oracle Database* | 1 to 65535 |
| *Limit Folder Depth* with *NTFS Security* | 1 to 127 |

## Schedule

*Frequency* section:

| Pattern | Meaning |
| - | - |
| *Once* | once – *Run Immediately* or *Choose Time* |
| *Daily* | every day at the same time |
| *Weekly* | on selected weekdays; at first all seven are selected |
| *Monthly* | on a day of the month, 1st to 31st |

The *Schedule* section below carries *Time*, *Start* and *End*. Dates in the past
are locked in all three date fields. *Time* accepts quarter hours only; a stored
value outside the grid is rounded down when the step is opened.

The closing button of the wizard is called *Run Now* with immediate execution,
otherwise *Schedule Job*.

## Results in the execution history

| Value | Means |
| - | - |
| *Running* | the execution is still going |
| *Succeeded* | executed, data captured |
| *Succeeded (No Data)* | executed, but nothing captured |
| *Warning* | executed, with objections |
| *Failed* | aborted, no data |
| *Failed (with data)* | aborted, but partly captured |
| *Discarded* | the execution was discarded |

The *Last result* column in the three job lists carries the same values.

## Gateway

The states of a gateway (*Online*, *Offline*, *Deleted*) and their consequences
are on [Managing Gateways](/docs/en/scan/gateway#reading-the-overview).
Installation and registration are in
[Installing and Registering the Gateway](/docs/en/scan/gateway-install).

Logging levels in the configuration: *Information*, *Warning*, *Error*, *Debug*,
*None*.

Six levels appear in the diagnostic log: *Error*, *Fatal*, *Warning*,
*Information*, *Debug* and *Verbose*. *Verbose* and *Fatal* cannot be set, *None*
does not occur in entries.

## Fixed sizes

| Value | Applies to |
| - | - |
| 5 days | advance warning for expiring credentials – from here the dashboard tile *Credentials Expiring* counts them (alongside entries already expired) |
| 24 hours | period of *Failed Scans* in *Action Required* |
| 7 days | period of the additional line with *Captured Assets* |
| 3 | entries in the dashboard section *Active Scans* |
| 6 | entries in the dashboard section *Gateways* |
| 30 seconds | time limit when saving a credentials entry |
| 15 minutes | grid of the *Time* field in the *Schedule* step |

## Terms

**Analysis package** — reusable compilation of server, shares, domain and
credentials for the *NTFS Security* module. Managed under
*Scan › Analysis Packages*.

**Job** — the named configuration of a scan module: gateway, targets,
credentials, schedule. Basis of the three lists *Active*, *Completed* and
*Failed*. The single pass is called an execution.

**One-time credentials** — access data passed along in the job and not saved. A
job like that cannot be executed again, only by entering the credentials again
through *Edit*.

**Entra ID app** — the app registration through which *Microsoft 365* and
*Microsoft Intune* access. At the same time the type of the associated
credentials entry.

**Gateway** — the Windows service in your own network that executes a job. Every
job hangs on exactly one gateway. The *Download Gateway* button delivers its
installer.

**Scan module** — the kind of source that is addressed.

**Storage location** — the column in *Scan › Credentials* that says where an
entry lies: *Vault* – encrypted at Docusnap365 – or *Gateway* – locally on a
gateway and read-only there. Creating and managing an entry on the gateway is in
[Storing Credentials Locally](/docs/en/scan/tutorial-credentials).

**Vault** — the encrypted store for credentials. Entries are encrypted in the
browser before they are transmitted.

**Unknown system** — a system that was found but not assigned to a type. On the
dashboard as *Unknown Systems* with the line *Typing pending*.

**Schedule** — the switch that decides whether a job is executed. *Pause* sets it
to inactive, *Resume* back to active.

## Related

Which modules exist and which steps they carry is in
[Scan Modules – Overview](/docs/en/scan/scan-modules). The wizard for any module is
described in [Creating a Scan Job](/docs/en/scan/create-inventory).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.