Configure Scan Engine properties
Configure the primary scanning capabilities and configuration options for scheduled, on-demand and real-time scans.
Before you begin
Reference these properties in preparation to Run your first scan with the Scan Engine or to make changes to Scan Engine behavior.
Role required: Scan Engine admin and Impact admin
Procedure
Navigate to ALL > Impact > Configuration > Scan Engine Properties.
Select Activate Scan Engine to ensure the Scan Engine runs against your instance.
Select Run Scheduled Scan to schedule nightly, weekly, or monthly scans, and then configure the following options.
| Schedule option | Description |
|---|---|
| Run | Daily, Weekly, or Monthly scheduled scan run times. |
| Day of Week | The day of the week on which to run weekly scans. |
| Day of Month | The day of the month on which to run monthly scans. |
| Time Zone | Your time zone. |
| Time | - Field type = `glide_utc_time` - The time the scan should begin in 24-hour format \(HH:MM:SS\). |
- Choose what to scan and how to track the findings.
| Setting | Description |
|---|---|
| Scan Non-Configuration Records | Includes non-configuration tables \(which do not extend `sys_metadata`\) in the scan. |
| Scan Read-Only Records | - Includes read-only records in the scan. - `scan_read_only`: Default value is `true`. - Read-only records are scanned by default. |
| Track Resolved Findings | Logs any resolved findings as part of the scan and includes them in the View Resolved Findings module of the dashboard. |
| Scan Findings Limit | - Field name: `scan_findings_limit` - The maximum number of findings that can be generated for each definition during a scan. - The limit is applied per applicable table. For example, if the limit is set to 100, a maximum of 100 findings will be generated for each applicable table. - Prevents excessive or redundant findings and optimizes scan performance. |
| Custom Workday | By default, technical debt is calculated as a 24-hour day, which allows you to specify a number of hours for a workday. For example, developer workdays can be set to 8 hours instead of 24.Note: This is used to calculate various metrics that appear in the Analytics Dashboards. |
| Average hourly rate of development | This figure calculates the cost of technical debt that displays on your dashboard by multiplying it by the estimated time to resolve each finding in the system. |
| Batch Record Size |
Note: This is a read-only system property that cannot be modified through the UI. |
| Scheduled Scan Logging Frequency | - Default value = `false` - Leave blank to disable verbose logging. When set, logs scan progress after processing the specified number of records |
| Days of scan finding histories to keep |
Note: This controls how long historical scan data is retained, not the findings themselves.The default value is 30 days. |
| Include review findings in technical debt | Displays findings on the dashboard where the level of the rule is equal to Review. |
| Enable instance specific definitions |
Note: Configuration option that controls whether definitions run only on specified instances. |
| Scan Non-Configuration Records | - Field name: `scan_non_configuration_records` - Default value = `true` - When enabled, includes non-configuration tables \(tables that do not extend sys\_metadata\) in full scans. |
Understand definition deactivation behavior and quota impact.
When you deactivate Scan Engine definitions, the system handles base system and custom definitions differently to ensure accurate entitlement tracking and prevent quota overages.
| Scenario | Behavior |
|---|---|
| Direct deactivation of base system definition | - The definition is deactivated via UI or API without creating an override record. - No override is recorded in the system. |
| Quota impact check after deactivation | - Deactivated base system definitions are excluded from active definition counts. - They do not count toward custom definition quotas. - System recalculates entitlements accurately when definitions change status. |
| Override-then-deactivate existing workflow | - When a base system definition is overridden and then deactivated, the behavior remains unchanged. - The deactivated override does not count as a custom definition. |
| Entitlement hashing integrity | - All combinations of base system and overridden definitions in active or inactive states produce consistent entitlement hash results. - No regressions occur for states that existed before this feature was introduced. |
**Note:** Deactivating a definition does not remove it from the system. It only changes the active status. If you need to completely remove a definition, contact your system administrator.
- Configure scanning properties per persona
You can view and configure a variety of information, formatted into lists, that the Scan Engine uses to permit users, team leads, and admins to access content. - Configure Scan Engine instance integration settings
You can view and configure a variety of information, formatted into lists, that the Scan Engine uses to implement its various scanning types. - Configure definition properties
You can configure additional capabilities and configuration options for the definition ruleset. - Configure real-time scanning properties
Real-time scanning properties allow control over which users have access to real-time scanning, and how the scan operates within their environment. Perform the following procedure to configure real time scanning properties. - Configure exception reason properties
When real-time enforcement,enforce_real_time_validationis set totrue, Recommend level findings require an approved exception reason before the form can be saved. - Configure update set scanning properties
The Scan Engine provides several options to further configure update set scanning and enhance the governance over update set management. Update set scanning occurs during scheduled instance scans. The settings on this tab define which update sets will be scanned, and the parameters those update sets have to meet in order to be marked complete.
Parent Topic:Activate Scan Engine and review settings