Scan Results and Host Scan Data

Host scan data is saved separately from saved scan results. When new scan results are available from an on demand or scheduled scan, the scan data is saved in two forms: saved scan results and host scan data.

Saved Scan Results (Manual data)

Saved scan results provide a view of your risk at a particular moment in time, the time of the scan task. Saved scan results are available on the scan history list for all finished scans.

To view saved scan results for a vulnerability scan, select Scan on the left menu, identify the scan you want to look at and click ico_view_lg.jpg. The complete results from the scan appear in a Scan Results report. You can also create Run Time reports based on Manual source selection to view vulnerability data from a single saved scan or to compare the results from multiple saved scans. The vulnerability data and hosts included in the report are specific to the saved scan results that you choose at run time.

Scan results may be deleted manually or automatically based on user configurations. Once deleted, the saved scan results are no longer available on the scan history list and may not be selected for Run Time reports. Note however that deleting scan results does not delete any host scan data. This means that you can delete all scan results for a particular host and still access the host scan data for that host in reports that are based on Auto source selection. See Deleting Scans for more information.

Host Scan Data (Auto data)

It is important to note that host scan data is based on saved scan results, and is updated automatically by the service each time a scan completes. Host scan data provides the most up-to-date information and current vulnerability status for each host. Host scan data, which is also referred to as Auto data, is used in Status and Status with Trend scan reports and scorecard reports. It is also displayed throughout the user interface including your Dashboard, asset search results, remediation tickets and host information.

To view host scan data, select Host Assets on the left menu, identify the host you're interested in, and click ico_info.jpg. The Host Information page appears displaying current host data.

To remove host scan data, the host must be purged. The service provides workflows for purging a single host and purging multiple hosts in bulk. See Purging Hosts for more information.

Important! Once purged, host information is not recoverable. Host information for purged hosts will not appear in reports until new scans are run and new host data is collected in your account.

When a host is purged, the following information from vulnerability scans is removed: information gathered on the host such as its hostname and OS, vulnerability history, remediation tickets for the host, and comments added to the host. Purging a host does not delete the saved scan results for the host. Additional host information may be removed if optional modules are enabled for your subscription. Compliance information collected from compliance scans will be removed when the compliance module is enabled. FDCC compliance information collected from FDCC scans will be removed when the FDCC module is enabled.

Hosts that have not been scanned do not have associated scan data. A host that is in your account may not have scan data even though it was scanned at some time. A host may not have scan data because the host was included in a scan target however the host was identified as not alive during host discovery and thus not scanned. A host will not have scan data if it was scanned, then purged, and not scanned again.