Sequential or unusual connection attempts across a range of ports and hosts get surfaced as a detection instead of getting lost in normal traffic noise.
Out of the box, Linivo flags a source host that touches more than 20 distinct destination ports on a single target, or more than 15 hosts on the same port, within a 60-second window.
Networks with legitimate broad scanning, like a vulnerability-management platform, should either be excluded by source IP or have their threshold raised under Detections > Port scan > Thresholds.
Route port-scan detections to a security-focused Slack channel or PagerDuty service distinct from your general alerting, since they usually need a different responder than a failing interface.