> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/security-testing-orchestration/3.0/use-sto/sto-custom-scanning-and-ingestion/custom-ingest-reference.md).

# Custom Ingest step for SARIF and JSON scan results

The Custom Ingest step enables you to ingest results from any third-party scanner. Harness STO supports two generic data formats:

* [SARIF](https://docs.oasis-open.org/sarif/sarif/v2.1.0/sarif-v2.1.0.html) is an open data format supported by many scan tools, especially tools available as GitHub Actions. You can easily ingest SARIF 2.1.0 data from any tool that supports this format. If your scanner can export to SARIF, use this format. For more information, go to [Ingest SARIF results](/security-testing-orchestration/use-sto/sto-custom-scanning-and-ingestion/ingest-sarif-data.md).
* Harness STO supports a custom JSON format that's useful for ingesting data from scanners that currently have no integration in STO and that cannot publish to SARIF. For more information, go to [Ingest Results from Unsupported Scanners](/security-testing-orchestration/use-sto/sto-custom-scanning-and-ingestion/ingesting-issues-from-other-scanners.md).

{% hint style="info" %}
The Custom Ingest step is intended for scanners that have no supported integration in STO. Harness recommends that you always use the documented workflow for supported scanners. For a list of all STO-supported scanners, go to [Supported Scanners](/security-testing-orchestration/3.0/new-to-sto/sto-whats-supported/scanners.md).
{% endhint %}

### For more information <a href="#for-more-information" id="for-more-information"></a>

### Custom Ingest step settings for STO scans <a href="#custom-ingest-step-settings-for-sto-scans" id="custom-ingest-step-settings-for-sto-scans"></a>

#### Scan <a href="#scan" id="scan"></a>

**Scan mode**

**Scan Configuration**

#### Target <a href="#target" id="target"></a>

**Type**

The target type of the scanned object. You can ingest data for the following target types:

* **Repository** Ingest scan results for a code repo.
* **Container image** Ingest scan results for the layers, libraries, and packages in a container image.
* **Instance** Ingest scan results for a running application.
* **Configuration** Ingest scan results for your cloud environment, generated by gathering configuration data via the cloud provider's APIs.

**Name**

**Variant**

#### Ingestion <a href="#ingestion" id="ingestion"></a>

**Ingestion File**

#### Log Level, CLI flags, and Fail on Severity <a href="#log-level-cli-flags-and-fail-on-severity" id="log-level-cli-flags-and-fail-on-severity"></a>

**Log Level**

**Additional CLI flags**

**Fail on Severity**

#### Additional Configuration <a href="#additional-configuration" id="additional-configuration"></a>

#### Advanced settings <a href="#advanced-settings" id="advanced-settings"></a>

### Proxy settings <a href="#proxy-settings" id="proxy-settings"></a>

### Custom Ingest pipeline examples <a href="#custom-ingest-pipeline-examples" id="custom-ingest-pipeline-examples"></a>

Here are some topics that describe end-to-end workflows for ingesting SARIF and JSON data:

* [Gitleaks step configuration](/security-testing-orchestration/3.0/use-sto/sto-scanner-configuration/gitleaks-scanner-reference.md)
* [Checkmarx step configuration](/security-testing-orchestration/3.0/use-sto/sto-scanner-configuration/checkmarx/checkmarx-scanner-reference.md)
* [Run scans using GitHub Action and Drone Plugin steps](/security-testing-orchestration/3.0/troubleshooting-and-resources/sto-use-cases/set-up-sto-pipelines/run-scans-using-github-actions.md)
* [Ingest JSON results from custom or unsupported scanners](/security-testing-orchestration/use-sto/sto-custom-scanning-and-ingestion/ingesting-issues-from-other-scanners.md)
