Skip to main content
The vijil discover command group is the command line interface for Discover. Every command acts on the team selected with vijil team use, so set that first.
Most commands accept --json for machine-readable output.
Every destructive command prompts for confirmation: deployment-delete, policy-delete, scanner-revoke, enrollment-code-revoke, spiffe-id-set and alert-rules-set. In a script, pass --yes or the command blocks waiting on input.

Setup

Collectors need this address at install time. See Install a Collector.

Targets

A Target is a place you want looked at.
The Console calls this object a Target. The command line and the API still call it a deployment, which is why these commands use the deployment-* name and the API path reads /v1/discover/deployments. They are the same object.
The response to deployment-create contains a live credential in plaintext. Never pipe it to a file or into a continuous integration log.

Collector Credentials

A Collector proves it belongs to a Target with a scanner token or an enrollment code. Minting requires --scanner-kind, and it accepts any string. The values in circulation are endpoint_linux, endpoint_macos, endpoint_windows, browser_ext, vpc_scanner, cloud_api_aws, and the one-shot kinds oneshot_easm, oneshot_egress, oneshot_logs, oneshot_idp and oneshot_gateway.

Scans

Reports

Resources

vijil discover inventory summarizes what Collectors found. Do not confuse it with the legacy cloud-inventory scans (the Resources page and the /v1/inventory API), which still ship where Discover is off.

Policies

Run policy-preview before policy-create to see what a policy matches before it starts producing violations.

Violations

Alerts

Runtime Events

These read from a dlp Target. A Vijil Dome proxy feeds it, and no scanning Collector reports into it.
Last modified on October 2, 2026