Monitor scans
4 min
monitor scans edition enterprise only scan monitoring has two surfaces in trufflehog enterprise scan details is the scans tab on an integration it covers the scan runs of that one integration how long each run scanned, how much of the source it covered, and the change in live secrets the activity log is a top level item in the main navigation it covers scan events across every source see activity log scan runs and events a scan run is one pass of an integration's scanner over its source scan details lists runs, one row per run the activity log lists events an event is a single moment in a run that trufflehog records, such as the run starting or the run failing one run writes several events, so the run you see as one row in scan details appears in the activity log as several rows statuses differ between the two for the same reason a status in scan details describes the run as a whole a status in the activity log describes one event retention scan runs and activity log events are both retained for 90 days where to look a single run looks wrong open the integration and check its scans tab for that run's status, duration, and coverage you need to know which parts of a source failed in a run open the scans tab and click the run's errors count a source keeps failing open the activity log and filter to that source to see how often it fails and when it last succeeded a run never started, or stopped before it scanned anything open the activity log and filter to that source failures of the run itself are recorded there, not in scan details you want scan health in your own tooling scan details and the activity log each have a read api