Recon Tasks

If you choose to edit or create a new task of network recon, then you should fill in the required fields in order the task could be processed properly.

Task name
Name of the discovery task. It's only a descriptive value to could distinguish the task in case it would have several of them with different values of filter or template.

Discovery server
Discovery Server assigned to the task. If you have several Discovery Servers, then you have to select here which of them you want to do the recon task.

Mode
Task Mode to choose between "Network Scanning" and "Script Custom". The first mode is the conventional network recognition task, and the second is the manner in which the task is associated with a custom script

Network
Network where you want to do the recognition. Use the network format/ bits mask. CIDR. For example 192.168.1.0/24 is a class C that includes the 192.168.1.0 to 192.168.1.255 adress.

Interval
Repetition interval of systems search. Do not use intervals very shorts so Recon explores a network sending one Ping to each address. If you use recon networks very larges (for example a class A) combined with very short intervals (6 hours) you will be doing that will be always bomb the network with pings, overloading it and also unnecessarily.

Module template
Plugins template to add to the discovered systems. When it detects a system that fits with the parameters for this task (OS, Ports), it will register it and will assign all the included modules in the defined plugin template.

OS
Operative system to recognize. If you select one instead of any (Any) it will only be added the systems with this operative system.Consider that in some circumstances can make a mistake when detecting systems, so this kind of "guess" is done with statistic patterns, that depending on some other factors could fail (networks with filters, security software, modified versions of the systems).To could use this method with security, you should have installed Xprobe2 in your system.

Ports
Define some specific ports or an specific range, e.g: 22,23,21,80-90,443,8080.If you use this field,only the detected hosts that will have at least one of the ports here mentioned will be detected and added to the system. If one host is detected but it has not at least one of the ports opened, then it will be ignored. This, along with the filter by OS kind allows to detect the systems that are interesting for us,e.g: detecting that it is a router because it has the ports 23 and 57 opened and the system detect it as a "BSD" kind.

Group
It is the group where we should add the discovered systems. It will must assign the new systems to one group. If it has already one specific group to locate the unclassified agents, then it could be a good idea to assign it there.

Incident
Shows if by discovering new systems it create an incident or not. It will create one incident by task, not one for detected machine,summarizing all the detected new systems, and it will create it automatically in the group previously defined.

SNMP Default community
Default SNMP community to use to discover the computers.

Comments
Comments about discovery network task.

OS detection
When choosing this option the scan will detect the OS.

Name resolution
When choosing this option, the agent will be created with the name the computer, long as it is configured in the equipment, if not create the agent with the IP name.

Parent detection
Selecting this option will detect in exploring whether computers connected to others and created as children.

Parent recursion
Indicates the maximum number of recursion with which agents will be able to generate as parents and children, after scan.