This section provides examples of running the ScanWin console application. There are three main sections:
The Discovery method determines how computer devices will be discovered on the network. Each discovered device will be pinged to determine if they are currently active on the network, and if they are they will be included in the scan.
The discovery methods available are outlined below.
To ensure proper data collection, the /fp (file package), /lu (last used), /rp (registry package), and /sl (software log) parameters must always be specified when using any of the discovery scan methods.
ScanWin must be ran from an administrative command prompt when running any of the commands below. Example:
- Click Start (also shown as the Windows logo in the Start menu).
- Type Command Prompt and right-click Command Prompt when it appears in the Start menu.
- From the resulting context menu, click Run as administrator.
To discover devices from Active Directory, the /domain parameter can be used. This will retrieve devices from the specified domain, and output a local file called AD_Computers.txt, which will be included when scanning. For example:
<p>ScanWin.exe /domain acmecorp.local /fp /lu /rp /sl</p>
To limit Active Directory discovery to a specific branch of the Organizational Unit tree, an LDAP address can be used. For example, to limit device discovery to just devices within the Computers OU in the acmecorp.local domain, the /domain parameter can be specified as:
<p>ScanWin.exe /domain CN=Computers,DC=acmecorp,DC=local /fp /lu /rp /sl</p>
To discover devices via an IP address range scan, the /iprange parameter can be used, specifying either the IP range in the format “from-to”, for example “10.211.55.1-10.211.55.255”, or via a CIDR network address, for example “10.211.55.1/24”. Both of these examples identify the same network range.
The IP address range scan uses ICMP to ping each IP address within the range, and each address that responds will be included in the inventory scan. Here is an example of using the "from-to" format:
<p>ScanWin.exe /iprange 10.211.55.1-10.211.55.255 /fp /lu /rp /sl</p>
Here is an example of using a CIDR network address format:
<p>ScanWin.exe /iprange 10.211.55.1/24 /fp /lu /rp /sl</p>
ScanWin will attempt to ICMP ping each IP address, and if there is a response, the IP address will be included in the inventory scan. If your environment is not configured to allow ICMP echo requests, it will need to be configured before using this method. More information for enabling ICMP options via Group Policy can be found here: https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-firewall/create-an-inbound-icmp-rule
To scan multiple devices from a device list, create a text file with one computer per line, for example:
# Lines starting with hashes act as comments and will be ignored.
ScanWin can read the file and scan each device using the /file parameter. For example:
<p>ScanWin.exe /file C:\ScanWin\computers.txt /fp /lu /rp /sl</p>
When credentials need to be entered to authenticate to devices, there are two options. First, the /user and /password command line switches can be used. For example:
<p>ScanWin.exe /computer ACMEPC01 /user User01 /password Pswrd01 /fp /lu rp /sl</p>
However, this is not best practice as the credentials are stored and displayed in plain text. The recommendation is to use the Secure Credentials Utility to generate encrypted credentials.
Importing and Exporting Data
Importing Data Stores
When using the Logon / Startup Script mode of operation, USB Drive method, or when multiple instances of ScanWin have been deployed, the data stores created by these can be imported into a central ScanWin instance, which will consolidate the scan results. For example:
<p>ScanWin.exe /import C:\ScanWin\Data</p>
Using ScanWin with the /export and /output parameters outputs a .CSV file prefixed with the base file name. For example:
<p>ScanWin.exe /export /output C:\ScanWin\Export\Acme-Corp</p>
This will export into the folder C:\ScanWin\Export, with the log file name having the prefix Acme-Corp. If the /output parameter is not specified, the export will output to .\Output.
Additionally, if the /exportfiles parameter is specified, any collected files are output within a CollectedFiles folder where there will be a subfolder for each device that has collected files, and a folder per file (as multiple files with the same name may be collected).
ScanWin persists the results of each scan in a local XML data store called DataStore.xml, and all devices that have been scanned within the last 90 days will be included in the output reports. This enables multiple scans to be combined into a single data export.
The .CSV file that is output from ScanWin can an be opened in Excel as a tabular report, where it can be filtered and reviewed.