Source archiving
7 min
source archiving edition enterprise only archiving stops trufflehog from scanning an integration source while keeping every finding it has already reported alternatively, you can permanently delete a source if you don't want to retain data associated with that integration source overview leverage integration source archiving when you want to retire an integration archiving preserves and retains the secrets associated with that source archiving is permanent if you need the source scanned again, you will need to setup a new integration archive delete scanning stops stops findings preserved destroyed reversible no no when to use retire the integration but keep the findings remove the integration and its data archiving is available in trufflehog enterprise only how it works archiving moves a source into an archived state three things follow from that scanning stops no new scans are scheduled, and a scan already in progress is stopped rather than left to finish this occurs whether the source runs on trufflehog's hosted scanners or a self hosted scanner verification freezes, but only when every source for a finding is archived a single secret is often reported by more than one source trufflehog stops re verifying a finding only when all of the sources that surfaced it are archived if the same secret is still visible to an active source, it keeps re verifying and behaves normally a frozen finding keeps its last known verification status and shows a verification frozen badge on the finding and in the secrets list frozen means that status is historical and won't update, not that the secret is invalid frozen findings are excluded from mttr archiving is recorded in the activity log archive a source archiving requires the admin or editor role viewers cannot archive a source go to integrations find the source you want to archive and click the three dot menu at the right of its row click archive read the confirmation dialog, which states that scanning stops permanently and findings are preserved, then confirm the source now shows a gray archived badge and drops out of the list, which hides archived sources by default if the request fails, the dialog stays open and shows the error inline view archived sources archived sources are hidden from integrations by default select show archived in the filter bar to include them they appear dimmed with a gray archived badge findings from archived sources are never hidden they stay visible and searchable in secrets whether or not archived sources are shown delete an archived source you can delete a source that you have already archived go to integrations and select show archived click the three dot menu on the archived source's row and click delete deleting is permanent and destroys the source's findings notes archived sources are excluded from active integration counts an archived source cannot be edited, re authorized, or scanned on demand scan now , edit , and any reauthorization option are removed from its three dot menu the verification frozen badge doesn't show a date the archive time is in the activity log entry creating a new source for the same system rescans it and surfaces the same secrets, but it starts with fresh triage state and does not inherit the archived source's history troubleshooting error cause solution archive does not appear in the three dot menu your role is viewer ask an admin or editor to archive the source a self hosted source keeps scanning after being archived the scanner is running a version that predates archive support upgrade the scanner no new scans are dispatched to it in the meantime, so the source stops scanning once the scanner recycles