cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
453
Views
0
Helpful
0
Replies

Cisco Secure Endpoint IOC Scans - Scanned 0 objects

Dan Jensen
Level 1
Level 1

Cisco Secure Endpoint

When initiating Full IOC scans we sometimes encounter the event log showing the results of the scan as (Scanned 0 objects. Found 0 matching objects and 0 malicious detections | Endpoint IOC Scan clean)

Normally we expect the event log of the scan to show man objects scanned and then the results of the scan (example: Scanned 74245916 objects. Found 0 matching objects and 0 malicious detections | Endpoint IOC Scan clean)

I have not been able to find any documentation or knowledge regarding this. Does this mean the scan did not scan anything when the event log shows "Scanned 0 objects."? Wouldn't this mean the scan is a failure if it literally didn't scan any objects?

We have been re-initiating IOC scans when we receive this result until the scan results show objects being scanned. Subsequent IOC scans will eventually return the results of objects being scanned.

Does anyone have any experience with this? Does anyone know the cause of the scan not being able to scan any objects?

0 Replies 0