Skip to content

Your first scan

After installing EdgeWatch, sign in as the administrator you created during setup.

Open Notifications and add a named Shoutrrr destination. Notification URLs are write-only: the console does not return an existing URL after you save it. Treat these URLs as secrets.

The notification guide covers routing, delivery health, and destinations imported from older deployments.

Open Scanner profiles. Keep the built-in profile to begin with, or create an administrator-managed profile suited to your network.

New TCP jobs default to Naabu connect discovery followed by Nmap confirmation. UDP always uses Nmap. Read Scanning and profiles before selecting SYN discovery or expanding the probe scope.

Create a job with:

  • Targets: authorized IP addresses, CIDRs, or DNS names.
  • Protocols and ports: the TCP and UDP surface you want to monitor.
  • Schedule: five-field cron syntax with the selected IANA timezone.
  • Baseline samples: how many successful samples establish the expected surface.
  • Change confirmation: how many matching changes confirm an incident.

Start with a small, known scope. Deployment probe budgets and target exclusions still apply to the job.

Run the job and inspect its results. Approve a successful scan as the baseline once you have verified that it represents the surface you expect.

Use Hosts to inspect effective addresses, ports, services, and scan evidence. Use Incidents to review confirmed changes.

  • Accept change makes the observed change expected and preserves scan history. Accepting a service on a newly opened port also accepts the port. Accepting only the port leaves its service for a separate decision.
  • Suppress 1 scan defers the alert for the next successful scan. If the change remains, it is reported again afterward.

Administrators and operators can take these incident actions. The jobs, baselines, and incidents guide also explains rebaselining, DNS aggregation, archival, and deletion.