Who is this article for?
Incydr Professional and Enterprise, yes.
Incydr Basic and Advanced, yes.
CrashPlan Cloud, no.
Other product plans, yes.
CrashPlan for Small Business, no.
This article applies to Code42 cloud environments.
When you enable file metadata collection, Code42 scans and indexes all files on user devices. (For Incydr Professional and Enterprise, file metadata collection is enabled automatically, so scanning begins immediately upon deploying the Code42 app to user devices.)
In addition, when you add a cloud data connection, Code42 scans and indexes all files in your organization's cloud drives.
This article answers frequently asked questions about this process, including:
- Endpoint data source: A single user device running the Code42 app.
- Cloud service data source: A corporate cloud service you authorize Code42 to monitor. Examples include Box, Google Drive, and Microsoft OneDrive for Business. This does not include email data sources (such as Gmail and Office 365 email) because there is no initial file scan for email services.
- Initial ingest: The file scan process that indexes all files on an endpoint data source. This scan is performed by the Code42 app installed on each device.
- Initial index: The file scan process that indexes all files in a cloud data source. This scan is performed via a direct connection between Code42 and the cloud service and does not involve the Code42 app on user devices.
What is the initial scan?
There are different scans for endpoints and for cloud data connections.
- Endpoint data source: The initial ingest scan indexes all files on the device.
- For Incydr Basic and Advanced and other plans, enabling File Metadata Collection initiates the scan. For Incydr Professional and Enterprise, the scan starts automatically.
- This ingest creates a record of all files on the device at the time file metadata collection was enabled. As a result, user devices might temporarily use a high percentage of CPU resources. Once the initial scan is complete, Code42 only monitors new and incremental file changes, using significantly fewer CPU resources.
- If you disable and then re-enable File Metadata Collection, the initial ingest file scan on the device starts over. (In Incydr Professional and Enterprise, there is no option to disable File Metadata Collection.)
- Cloud service data sources: The initial index scans and indexes all files in your organization's cloud drives. This scan does not affect user devices at all. Code42 connects directly to the cloud service to capture this data, and simultaneously starts monitoring file activity right away while completing the initial index. New files are typically discovered a few minutes after they are created.
Shared libraries in Microsoft are not indexed, discovered, or monitored
Code42 can only monitor drives in Microsoft OneDrive. While you can create a shared library within OneDrive, such libraries are actually created as Team Sites in SharePoint. Because Code42 cannot monitor sites in SharePoint, any shared libraries listed in your OneDrive environment are excluded.
How long does the scan take?
- Endpoint data source: Ingest times vary based on the number and size of files on each device. The processing power of the device and your Code42 CPU usage settings also affect how long it takes to complete. With the recommended CPU usage settings of 50% When user is away and 20% When user is present, devices can take several hours to several days to scan every file on the device. (CPU settings are not configurable in Incydr Professional and Enterprise.)
- Cloud service data sources: The length of time it takes for initial indexing to complete is dependent on the number of drives in your environment.
- For environments that contain hundreds of drives, initial indexing may take between 24 and 72 hours depending on the number of files in each user's drive.
- For environments that contain thousands of drives, initial indexing completes over a longer period. Typically, drives in larger environments complete the indexing process over these time frames:
- 60% of total drives complete between 24 and 72 hours
- 25% of total drives complete between 3 and 5 days
- 15% of total drives complete between 6 and 10 days
Can I start viewing file activity before the scan is fully complete?
- Endpoint data sources: Yes. As soon as a file is scanned and indexed, file events for that file are visible in Code42. In addition, file activity that may indicate an exposure risk (such as moving files to removable media, uploading to personal cloud services or email) are given priority over indexing all files on the device and are reported in near real-time.
- Cloud data sources: Yes. Code42 starts monitoring file activity in your organization's environment right away while scanning and indexing drives. File events for all drives become available in Code42 soon after they occur, even if drives have not completed indexing.
How do I know when the scan is complete?
Endpoint data source
Scan status is visible in the Code42 app logs for each device:
- Sign in to the Code42 console.
- Select Administration > Devices.
- Select a device.
The device details appear.
- Retrieve the logs:
- Incydr Basic and Advanced and other plans: From the action menu, select Retrieve Logs.
- Incydr Professional and Enterprise: Select Actions > Retrieve Logs, then click Retrieve Logs.
- In the Retrieve log: Email notification dialog, select Yes and enter an email address to receive an email notification, or select No.
- Click Apply.
Retrieving... displays under the Logs URL column of the table. (If the device is offline, Retrieving... displays until the device is online.) When the logs are available, a Download logs link displays.
- Click the Download logs link.
The logs are downloaded in a ZIP file.
- Navigate to the location of the downloaded log archive and open the archive.
- Locate and open the service.log.0 file.
- Search the service.log.0 file for these strings, which indicate the initial scan is complete:
Transitioned FFS ingest state from INITIAL_INGEST to SCAN_SUCCESS
Transitioned FFS ingest state from SCAN_SUCCESS to STEADY_STATE
If the above strings do not appear in the log file, the scan is still in process, or the scan completed long enough ago that the messages exist in an older version of the log file (for example service.log.1 or service.log.2).
Contact our Customer Champions for support if you need help determining the scan status for a device.
Cloud service data sources
In the Code42 console, go to Administration > Integrations > Data Connections and review the Status column.
- A status of Monitoring indicates initial indexing of all drives is complete. This status may change to Monitoring, indexing in progress when new drives are discovered.
- A status of Searching for drives or Monitoring, indexing in progress indicates that initial indexing has not yet completed.
- The Searching for drives status indicates that Code42 has established a connection to the cloud service and is discovering all of the in-scope drives that it contains.
- The Monitoring, indexing in progress status indicates that all drives in your cloud environment are being monitored for file activity. At the same time, each drive is being scanned and indexed as part of the initial index process.
- To view more detailed status information, click a row in the Data Sources table to open the details panel for that cloud service. This panel lists the following values:
- The total number of drives that Code42 has discovered and is currently monitoring for file activity
- The number of drives for which the initial index is still in progress
- The number of drives that have completed the initial index process
Why is a device using more CPU than the max allowed?
Does not apply to Incydr Professional and Enterprise
Because the initial scan reviews and indexes all files on a device, user devices might temporarily use a high percentage of CPU resources.
Code42 app CPU settings apply to the amount of CPU processing time dedicated to Code42, not to total CPU processing capacity. Therefore, if the CPU limit is to 20% (for example), the device's Task Manager or Activity Monitor may report the Code42 app is using more than 20% of the CPU at a particular point in time.
The processing time of the CPU is measured in instruction cycles. When you limit CPU use for the Code42 app to X%, you are specifying that the Code42 app is allowed use as much of the CPU capacity as it needs for up to X% of the available cycles. For example, if the CPU limit is set to 20%, the Code42 app can use up to 100% of the CPU 20% of the time. The remaining 80% of the time, the CPU prioritizes other process requests. This allows the Code42 app to work as efficiently as possible when it requests CPU resources, but limits the overall impact to the device.
For the best mix of performance and speed, we recommend setting the When user is away, use up to setting to 50% and the When user is present, use up to setting to 20%.
How much memory does Code42 use?
The Code42 app dynamically sets memory allocation to use 25% of the physical memory on the device. For example, if the device has 8GB of RAM, the Code42 app can use up to 2GB.