Enterprise Recon 2.0.27

Start a Scan

This section assumes that you have set up and configured Targets to scan. See Targets Overview.

Start a scan from the following places in the Web Console:

To Start A Scan

  1. In DASHBOARD, TARGETS, or SCHEDULE MANAGER, click Start Search.
    er2-start-search.png
  2. On the Select Locations page, select Targets to scan from the list of Targets and click Next.

  3. On the Select Data Types page, select the Data Types to be included in your scan and click Next. See Data Type Profiles.
  4. Set a scan schedule in the Set Schedule section. Click Next.
  5. Click Start Scan.

Your scan configuration is saved and you are directed to the TARGETS page. The Target(s) you have started scans for should display Searched x.x% in the Searched column to indicate that the scan is in progress.

Set Schedule

The Set Schedule page allows you to configure the following optional parameters for your scan:

er2-schedule-basic.png

Schedule Label

Enter a label for your scan. ER2 automatically generates a default label for the scan. The label must be unique, and will be displayed in the SCHEDULE MANAGER. See View and Manage Scans.

er2-schedule-label.png

Scan Frequency

Decide to Scan Now, or to Schedule a future scan.

To schedule a scan:

  1. Select Schedule.
  2. Select the start date and time for the scan.
  3. (Optional) Set the scan to repeat by selecting an option under How Often?.

er2-schedule-frequency.png

When scheduling a future scan, you can set a Time Zone. The Time Zone should be set to the Target host’s local time.

Selecting the “Default” Time Zone will set the scan schedule to use the Master Server local time.

Setting the time zone
  • Time Zone settings take into account Daylight Saving Time (DST).
  • Setting the Time Zone here will affect the time zone settings for this scheduled scan only.

Set Notifications

To set notifications for the scan:

  1. Select Notify.
    er2-after-search-notifications.png
  2. Click + Add Notification.
  3. In the New Notification dialog box :
    • Select Users to send alerts and emails to specific users.
      er2-after-search-notifications-add-users.png
    • Select Email Addresses to send email notifications to specific email addresses.
      er2-after-search-notifications-add-emails.png
  4. Under Notification Options, select Alert or Email for the event to send notifications for when the event is triggered. Only the Email options are available if Email Addresses is selected in step 3.
  5. Click Save.

See Notifications and Alerts for more information.

Advanced Options

Configure the following scan schedule parameters in Advanced Options:

Automatic Pause Scan Window

Set scan to pause during the scheduled periods:

  • Pause From: Enter the start time (12:00 am - 11:59 pm)
  • To: Enter the end time (12:00 am - 11:59 pm)
  • Pause on which days?: Select the day(s) on which the scan is paused. If no days are selected, the Automatic Pause Scan Window will pause the scheduled scan every day between the times entered in the Pause From and To fields.
Set a scan pause schedule for every Wednesday and Friday from 8:00 am to 12:00 pm:

If a Time Zone is set, it will apply to the Automatic Pause Scan Window. If no Time Zone is set, the Time Zone menu will appear under How Often?, allowing the user to set the time zone for the scan. See Scan Frequency above for more information.

Limit CPU Priority

Sets the CPU priority for the Node Agent used.

If a Proxy Agent is used, CPU priority will be set for the Proxy Agent on the Proxy Agent host.

The default is Low Priority to keep ER2’s resource footprint low.

Limit Search Throughput

Sets the rate at which ER2 scans the Target:

  • Limit Data Throughput Rate: Select to set the maximum disk I/O rate at which the scanning engine will read data from the Target host. No limit is set by default.
  • Set memory usage limit: Select to set the maximum amount of memory the scanning engine can use on the Target host. The default memory usage limit is 1024 MB.

er2-schedule-advanced-limitthroughput.png

Trace Messages

Logs scan trace messages for the scanned Targets, select Enable Scan Trace. See Scan Trace Logs.

Capture Context Data

Select to include contextual data when displaying matches in the Match Inspector. See Remediation.

Probe Targets

From ER 2.0.21, you can probe Targets to browse and select specific Target locations to scan when adding a new Target.

Requirements

Make sure that:

  • The Master Server is running ER 2.0.21 or above. See Update ER2.
  • The version of the Node or Proxy Agent assigned to the Target is 2.0.21 or above. For details on how to install or update the Agent, see Manage Agents.
  • The Target host and the Node or Proxy Agent assigned to the Target are running and connected to the network.

To Probe Targets

  1. Start a new scan.
  2. In Select Locations, click the arrow next to the Target name to expand and view available locations for that Target.
    er2-browseTarget.png
  3. Select the Target location(s) to scan.
    er2-browseTarget2.png
  4. Click Next to continue configuring your new scan.