You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/references-data-retention.md
+9-23Lines changed: 9 additions & 23 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -13,8 +13,6 @@ Each storage location affords a certain storage capacity and retention times. Th
13
13
14
14
## Devices retention periods
15
15
16
-
<!--need to understand if this data retention is only OT devices or also Enterprise IoT devices. Can you ask Theo? Also - are there any differences for the EIoT sensor?-->
17
-
18
16
| Storage type | Details |
19
17
|---------|---------|
20
18
|**Azure portal**| Device inventory data is stored for 90 days from last seen/activity field. <br><br> For more information, see [Manage your device inventory from the Azure portal](how-to-manage-device-inventory-for-organizations.md). |
@@ -23,27 +21,21 @@ Each storage location affords a certain storage capacity and retention times. Th
23
21
24
22
## Alert data retention
25
23
26
-
<!--need to understand if this data retention is only OT alerts or also Enterprise IoT alerts, which are coming up. Can you ask Theo? Also are there any differences for the EIoT sensor?-->
27
-
28
24
Alert data is retained as listed below, regardless of the alert's status, or whether it's been learned or muted.
29
25
30
26
| Storage type | Details |
31
27
|---------|---------|
32
28
|**Azure portal**| Alerts are stored on the Azure portal for 90 days from their first detection time. <br><br> For more information, see [View and manage alerts from the Azure portal](how-to-manage-cloud-alerts.md). |
33
-
|**OT network sensor**| Alerts are stored on the local sensor for 90 days from their first detection time. <br><br> For more information, see [View alerts on your sensor](how-to-view-alerts.md). |
29
+
|**OT network sensor**| Alerts are stored on the OT sensor for 90 days from their first detection time. <br><br> For more information, see [View alerts on your sensor](how-to-view-alerts.md). |
34
30
|**On-premises management console**| Alerts are stored on the on-premises management console for 90 days from their first detection time. <br><br> For more information, see [Work with alerts on the on-premises management console](how-to-work-with-alerts-on-premises-management-console.md). |
35
31
36
32
### OT alert PCAP data retention
37
33
38
-
<!--i'm pretty sure that PCAP files are OT only-->
39
-
40
34
| Storage type | Details |
41
35
|---------|---------|
42
36
|**Azure portal**| PCAP files are available for download from the Azure portal for as long as the OT network sensor stores them. <br><br> Once downloaded, the files are cached on the Azure portal for 48 hours. <br><br> For more information, see [Access alert PCAP data (Public preview)](how-to-manage-cloud-alerts.md#access-alert-pcap-data-public-preview). |
43
-
|**OT network sensor**| PCAP files are stored on the OT sensor for up to 90 days, depending on the sensor's storage capacity. <br><br> Maximum size of filtered PCAPs allowed is 133,120 MB. <br> If you exceed this size, the oldest backed-up file is deleted to accommodate the new one. <br><br> For more information, see [Download PCAP files](how-to-view-alerts.md#download-pcap-files). |
44
-
|**On-promises management console**| PCAP files aren't stored on the on-premises management console. <br><br> Access PCAP files from the on-premises management console using a direct link to hte sensor, for as long as the on premises sensor stores them. |
45
-
46
-
<!--we say later that these are configurable. where? -->
37
+
|**OT network sensor**| PCAP files are stored on the OT sensor for up to 90 days, depending on the sensor's storage capacity. <br><br> Maximum size of filtered PCAPs allowed is set by default to 133,120 MB, but configurable in the `filtered.cache.dir.size.megabytes.max` property in the *pcap.properties* file.<br> If you exceed this size, the oldest backed-up file is deleted to accommodate the new one. <br><br> For more information, see [Download PCAP files](how-to-view-alerts.md#download-pcap-files). |
38
+
|**On-promises management console**| PCAP files aren't stored on the on-premises management console. <br><br> Access PCAP files from the on-premises management console using a direct link to the sensor, for as long as the on premises sensor stores them. |
47
39
48
40
## Security recommendation retention
49
41
@@ -77,34 +69,28 @@ Only service and processing log files are stored on the Azure portal, and are re
77
69
78
70
Other OT network monitoring log files are stored only on the OT network sensor and on-premises management console.
79
71
80
-
On both the OT sensor and the on-premises management console, older log files are overridden when the appliance's storage has reached its maximum capacity. Log file sizes differ depending on the amount of content, but the average size per log file is 100-150 MB.<!--you'd written log here, not log file. I assume it's log file since each indidvidual log would be much, much smaller, no?-->
72
+
On both the OT sensor and the on-premises management console, older log files are overridden when the appliance's storage has reached its maximum capacity. Log file sizes differ depending on the amount of content, but the average size per log file is 100-150 MB.
81
73
82
-
<!-- `There are numerous different kinds of log files, and they have different storage capacities.` Is there other data we're not including here? Why aren't we including it? I think we should if we can. This statement leaves me with questions.-->
83
-
84
-
<!-- `Some of the logs have rotation and the data isn't overridden immediately.` Not sure what this means? Also, lets avoid words like "some" - which just leaves me with the question of "which"? can we clarify what this means?-->
85
-
86
-
<!--for more information, see ... what? Maybe the troubleshooting article?-->
74
+
For more information, see:
87
75
88
-
<!--what about log files on the Enterprise IoT sensor? Can you ask Nimrod / Theo?-->
76
+
-[Troubleshoot the sensor and on-premises management console](how-to-troubleshoot-the-sensor-and-on-premises-management-console.md).
77
+
-[Download a diagnostics log for support](how-to-manage-individual-sensors.md#download-a-diagnostics-log-for-support).
89
78
90
79
## On-premises backup file capacity
91
80
92
81
Both the OT network sensor and the on-premises management console have automated backups running daily, which are stored as follows:
93
82
94
83
| Storage type | Details |
95
84
|---------|---------|
96
-
|**OT network sensor**| The maximum size of sensor backup files stored on the sensor itself is 100 GB. Older backup files are deleted if the total backup file size passes this limit. <br><br>However, each sensor also has its own, extra backup directory on the on-premises management console. <br><br> For more information, see [Set up backup and restore files](how-to-manage-individual-sensors.md#set-up-backup-and-restore-files). |
97
-
|**On-promises management console**| The following types of backup files are stored on the on-premises management console, each with their own maximum file size: <br><br> - **On-premises management console backup file**: Set by default to 10 GB, but configurable in the `backup.max_directory_size.gb` property.<br> - **OT sensor backup files**: Set by default to 40 GB, but configurable in the `sensors_backup.total_size_allowed.gb` property.|
85
+
|**OT network sensor**| The maximum size of sensor backup files stored on the sensor itself is set by default to 100 GB, but configurable in the `max_directory_size_in_gb` property in the *backup.properties.configurable* file. <br><br> Older backup files are deleted if the total backup file size passes this limit. <br><br>However, each sensor also has its own, extra backup directory on the on-premises management console. <br><br> For more information, see [Set up backup and restore files](how-to-manage-individual-sensors.md#set-up-backup-and-restore-files). |
86
+
|**On-promises management console**| The following types of backup files are stored on the on-premises management console, each with their own maximum file size: <br><br> - **On-premises management console backup file**: Set by default to 10 GB, but configurable in the `backup.max_directory_size.gb` property in the *backup.properties.configurable* file.<br> - **OT sensor backup files**: Set by default to 40 GB, but configurable in the `sensors_backup.total_size_allowed.gb` property in the *backup.properties.configurable* file. <br><br> For more information, see [Set up backup and restore files](how-to-manage-individual-sensors.md#set-up-backup-and-restore-files)|
98
87
99
88
For more information, see:
100
89
101
90
-[Configure backup settings for an OT network sensor](how-to-manage-individual-sensors.md#set-up-backup-and-restore-files)
102
91
-[Configure OT sensor backup settings from an on-premises management console](how-to-manage-sensors-from-the-on-premises-management-console.md#backup-storage-for-sensors)
103
92
-[Configure backup settings for an on-premises management console](how-to-manage-the-on-premises-management-console.md#define-backup-and-restore-settings)
104
93
105
-
<!--what about backup files on the Enterprise IoT sensor? Can you ask Nimrod / Theo?-->
106
-
<!-- these parameter names. we don't mention them anywhere else in the docs. are we sure we want to mention them now? I'd almost prefer to open a separate user story to add how-tos to the docs for how to configure these values, and leave this now as the default only. please check with the SMEs on this one-->
0 commit comments