Scan details
10 min
scan details edition enterprise only scan details lists the scan runs for one integration, showing the duration of the scan, scan coverage, and new live secrets for a consolidated list of scan events across every source, see activity log docid\ tv2tlkzenoxh9tnpzg3sa overview open the scans tab on an integration to gather information about the scan scan runs are recorded automatically and do not require additional configuration scan details provide scan visibility per integration scan details is available in trufflehog enterprise ui and through a read api see the api reference for endpoints, filters, and response fields how it works each row is one scan run, meaning one pass of this integration's scanner over the source a run's counts describe that pass alone coverage is counted in the items a source contains, not in secrets the column is named for the item type repository for github and gitlab, project for jira, space for confluence, bucket for s3, path for filesystem a source with no specific item name uses item a run showing 95 of 98 with 3 in errors attempted 98 items and successfully scanned and verified 95 errors are aggregated in the table and itemized the errors column carries the number of items that failed opening it lists those items with their individual error messages failures of the run itself, where the scan did not proceed, are recorded in the activity log docid\ tv2tlkzenoxh9tnpzg3sa rather than here count accuracy depends on the run's final status completed and completed with errors runs report exact figures a failed run can terminate before its counts are finalized, so its figures are a lower bound on what it attempted an absent count and a zero count are distinct means no figure was recorded for the run 0 means the run recorded a count of zero live secrets change is a run over run delta it reports the difference against the source's previous run, so +5 means five more live secrets after this run than after the last a source's first run has no predecessor, so its full count is reported as new the end of run total is available on hover in progress rows populate as the scan proceeds, and finished rows do not change the table polls for updates while a run is active and the scans tab is open, then stops once the run reaches a final status availability of scan details depends on the source type columns column shows status the run's status, as an icon and a label start time when the run began, for example sep 8, 2026 at 11 34pm active duration time the scanner spent executing the run repository , bucket , path , and so on items scanned against items found, as 95 of 98 the column name depends on the source type errors items that failed opens those items in a drawer when the count is above zero live secrets change the change in the source's live secret count since its previous run statuses status meaning started the run has been created and is initializing no items have been scanned yet this state lasts seconds, so a run that remains in it failed to initialize in progress the scanner is enumerating and scanning the source's items completed every item in scope was scanned and none failed completed with errors the run reached the end of the source's items and one or more failed failed the run stopped before it finished its pass over the source completed with errors and failed differ in what they imply about coverage a completed with errors run reached the end of the source, so the errors count is a complete account of what was missed a failed run stopped early, so coverage is incomplete and what went unscanned is not yet known view scan runs for an integration scan details is available to admins and editors on any other role the scans tab reads you don't have access to scan details go to integrations and select the integration's source type click the view details button for the integration open the scans tab each row is one scan run the table lists 10 runs per page, newest first a source that has never completed a run reads no scan runs are available yet sort the scan list click a column header everything sorts except status and live secrets change click the same header again to reverse the direction the header you sorted by shows a direction arrow and the table returns to page 1 sorting covers every run in the integration's history, not just the runs on the current page sorting by a second column clears the first investigate a run's errors find a run whose errors count is above zero click the count a drawer opens from the right search the drawer by name, or expand an entry to read its error the drawer lists only the items that failed while the run is active, the list updates as further failures are recorded if the count is above zero but reads as plain text rather than a link, the run's error details are no longer stored filter the activity log docid\ tv2tlkzenoxh9tnpzg3sa to the source for its scan level failure events instead notes scan runs are kept for 90 days use the read api to pull scan runs into your own reporting scan history starts with the first run recorded after scan details becomes available for your account earlier runs are not backfilled if the table reads couldn't load scan runs , click try again troubleshooting condition cause solution a failed run shows — instead of counts the run stopped before it finished counting, so there is no figure to show it does not mean the run scanned nothing filter the activity log to the source to read the failure message the drawer says error details are no longer available the run is old enough that its error details have been cleared, even though the run itself is still listed use the activity log for the source's scan level events from that period active duration is much shorter than the time you waited it measures how long the scanner worked, not how long the run took waiting for a free scanner does not count, and parts of a source that scan at the same time count once instead of adding up nothing to fix compare start time between two runs for elapsed time