Troubleshoot Low Scan Health

Use this guide when the Optimizer reports Low Health for a Scan.

Low Scan Health can indicate that problems during execution affected Bright's ability to reach and test the expected application scope. Review the Scan details to identify target, authentication, blocking, Repeater, scope, or configuration issues.

1. Confirm the target application is available

Check that the target was available and stable during the Scan.

  • Open the application manually.
  • Verify that the target URL loads correctly.
  • Check application uptime and response time.
  • Review repeated application errors or failed requests.
  • Check DNS resolution and TLS configuration.

If the target temporarily stopped responding or DNS resolution failed and Bright automatically paused the Scan, fix the issue and resume the existing Scan.

If the Scan is already in a terminal state, fix the issue and start a new Scan.

2. Verify authentication

If the Scan tests protected areas, confirm that authentication still works.

Check that:

  • The configured credentials are valid.
  • The Authentication Object still exists and belongs to the correct project.
  • The Authentication Object target is reachable.
  • The application's login or authentication flow has not changed.
  • The authenticated session can still access the expected application areas.

Authentication problems can prevent Bright from reaching protected parts of the application.

3. Check WAF, bot protection, and rate limits

Security controls can block or limit Scan traffic.

Check whether the target uses:

  • A Web Application Firewall (WAF).
  • Bot protection.
  • CAPTCHA.
  • Rate limiting.
  • Firewall rules that may block Bright traffic.

Review these controls and make sure Bright can reach and test the intended target.

4. Review Scan scope and entry points

Confirm that the Scan is configured to test the expected application scope.

Check:

  • The configured target and starting URL.
  • The entry points included in the Scan.
  • Dynamic entry point filters.
  • Whether important application areas are represented by the available entry points.
  • Whether a recent Discovery contains the expected application entry points.

If no entry points match a dynamic filter, review the filter and broaden it if appropriate. If the expected entry points do not exist in the project, run a Discovery first.

5. Check application behavior

Application behavior can affect Bright's ability to reach and test the expected scope.

Look for:

  • Broken or unavailable pages.
  • Repeated application errors.
  • Redirect loops.
  • Pages or endpoints that fail to load.
  • Recent application changes that may affect navigation or authentication.

If the application changed recently, compare the affected Scan with a previous successful execution.

6. Check Repeater connectivity and resources

If the Scan uses a Repeater, confirm that it remained connected and responsive throughout the execution.

Check:

  • Repeater connection status.
  • CPU and memory usage on the Repeater host.
  • Network stability.
  • Outbound connectivity from the Repeater to Bright.
  • Connectivity from the Repeater to the target.
  • Whether the Repeater service crashed or restarted.

A disconnected, overloaded, or unstable Repeater can disrupt a Scan.

7. Review execution issues

Review the Scan execution details for errors related to:

  • Target connectivity.
  • Repeater connectivity.
  • Authentication.
  • Scan configuration.
  • Entry points.
  • Bright engine or service errors.

Resolve the reported execution issue before running the Scan again.

8. Review Scan size

Very large executions can consume more resources and may fail if the engine runs out of memory.

If the Scan contains a very large number of entry points:

  1. Reduce the scope where appropriate.
  2. Split the Scan into smaller executions.
  3. Start a new Scan.

If memory-related errors continue for a normal-sized Scan, contact Bright Support.

Confirm that Scan Health improved

After resolving the identified issue, run or resume the Scan as appropriate.

Confirm that:

  • The Scan continues or completes successfully.
  • Target and Repeater connectivity remain stable.
  • Authentication works as expected.
  • The expected entry points are tested.
  • The same execution errors do not occur again.

When to contact Bright Support

Contact Bright Support if Scan Health remains low after completing these checks or if the same execution issue continues to occur.

Include:

  • Scan ID.
  • Target URL.
  • Approximate Scan time.
  • Whether authentication was configured.
  • Relevant error messages or error codes.
  • Whether a Repeater was used.
  • Whether a WAF, CAPTCHA, bot protection, or rate limiting is enabled.

Did this page help you?