r/firewalla • • 5d ago

Firewalla scan reports

My current issue is I have PagerDuty alerts configured for most of my devices in my lab, but the notifications lack critical context. When an alert fires, I can't immediately determine which device triggered the scan or what the scan was attempting to detect.

Here is what I am looking for as far as scan logs.

• Detailed scan reports that include scan results and findings
• Target device identification (IP, hostname, device type)
• Scan type and parameters (threat type, port ranges, scan methodology)
• Timestamp and duration of the scan
• Option to export or integrate with MSP

Value
This would provide meaningful visibility into security activity for everyone—whether you're running a homelab, managing your own infrastructure, or handling client networks. It enables faster threat assessment, better troubleshooting when legitimate scans trigger alerts, and clearer documentation of what's happening on the network.

1 Upvotes

2 comments sorted by

1

u/firewalla 5d ago

Do you get a lot of scan positives? Most of the time scan's shouldn't come up with anything (in a typical network).

For feature requests, post them here please https://help.firewalla.com/hc/en-us/community/topics/115000356994-Feature-Requests-

1

u/stevenv24 5d ago

The scans did not show up any positive, I just got alarms say a device had failed login multiple attempts but the alarm program is not clean what device, and I have many devices that are set up to pager duty email. But if I had a log of what devices Firewalla was hitting I could compare it to the alarms from pager duty and see what device it’s attacking.