Monitoring
Running a network discovery scan
Finding the devices your agent inventory cannot see, and interpreting the results responsibly.
Last updated
Agent-based inventory has a structural blind spot: it can only tell you about machines that have an agent. Everything else on the segment — printers, switches, access points, cameras, appliances, and the machine somebody plugged in without telling you — is invisible to it. Network discovery is the answer to that.
A scan runs on demand against a network range and returns the devices that responded. Results land in a discovered-device register that is held separately from agent-managed endpoints. That separation is deliberate and worth protecting: the moment discovered devices and managed devices share a list, someone quotes the combined number as "devices under management" and it ends up in front of a customer.
Run discovery when you take on a new client or site, and periodically thereafter. The first scan of a new environment is routinely the most informative thing you do that week. What it finds is rarely exotic; it is usually a handful of machines nobody mentioned, network equipment that was not in the handover documentation, and at least one device whose purpose no one at the client can explain.
Read the results with appropriate caution. A scan reports what responded on the network at the moment it ran. Machines that were powered off do not appear. Devices behind segment boundaries the scan did not cross do not appear. And a device appearing on a segment is not evidence that it belongs there — that judgement is yours.
Discovery is also the honest starting point for a coverage conversation. If a client believes they have ninety managed machines and discovery finds a hundred and twenty responding devices, the gap is worth understanding before it becomes either a security finding or a billing dispute. Often it is both.