Skip to content

Commit 3699199

Browse files
committed
update after SME feedback
1 parent 78e4ffd commit 3699199

File tree

1 file changed

+9
-23
lines changed

1 file changed

+9
-23
lines changed

articles/defender-for-iot/organizations/references-data-retention.md

Lines changed: 9 additions & 23 deletions
Original file line numberDiff line numberDiff line change
@@ -13,8 +13,6 @@ Each storage location affords a certain storage capacity and retention times. Th
1313

1414
## Devices retention periods
1515

16-
<!--need to understand if this data retention is only OT devices or also Enterprise IoT devices. Can you ask Theo? Also - are there any differences for the EIoT sensor?-->
17-
1816
| Storage type | Details |
1917
|---------|---------|
2018
| **Azure portal** | Device inventory data is stored for 90 days from last seen/activity field. <br><br> For more information, see [Manage your device inventory from the Azure portal](how-to-manage-device-inventory-for-organizations.md). |
@@ -23,27 +21,21 @@ Each storage location affords a certain storage capacity and retention times. Th
2321

2422
## Alert data retention
2523

26-
<!--need to understand if this data retention is only OT alerts or also Enterprise IoT alerts, which are coming up. Can you ask Theo? Also are there any differences for the EIoT sensor?-->
27-
2824
Alert data is retained as listed below, regardless of the alert's status, or whether it's been learned or muted.
2925

3026
| Storage type | Details |
3127
|---------|---------|
3228
| **Azure portal** | Alerts are stored on the Azure portal for 90 days from their first detection time. <br><br> For more information, see [View and manage alerts from the Azure portal](how-to-manage-cloud-alerts.md). |
33-
| **OT network sensor** | Alerts are stored on the local sensor for 90 days from their first detection time. <br><br> For more information, see [View alerts on your sensor](how-to-view-alerts.md). |
29+
| **OT network sensor** | Alerts are stored on the OT sensor for 90 days from their first detection time. <br><br> For more information, see [View alerts on your sensor](how-to-view-alerts.md). |
3430
| **On-premises management console** | Alerts are stored on the on-premises management console for 90 days from their first detection time. <br><br> For more information, see [Work with alerts on the on-premises management console](how-to-work-with-alerts-on-premises-management-console.md). |
3531

3632
### OT alert PCAP data retention
3733

38-
<!--i'm pretty sure that PCAP files are OT only-->
39-
4034
| Storage type | Details |
4135
|---------|---------|
4236
| **Azure portal** | PCAP files are available for download from the Azure portal for as long as the OT network sensor stores them. <br><br> Once downloaded, the files are cached on the Azure portal for 48 hours. <br><br> For more information, see [Access alert PCAP data (Public preview)](how-to-manage-cloud-alerts.md#access-alert-pcap-data-public-preview). |
43-
| **OT network sensor** | PCAP files are stored on the OT sensor for up to 90 days, depending on the sensor's storage capacity. <br><br> Maximum size of filtered PCAPs allowed is 133,120 MB. <br> If you exceed this size, the oldest backed-up file is deleted to accommodate the new one. <br><br> For more information, see [Download PCAP files](how-to-view-alerts.md#download-pcap-files). |
44-
| **On-promises management console** | PCAP files aren't stored on the on-premises management console. <br><br> Access PCAP files from the on-premises management console using a direct link to hte sensor, for as long as the on premises sensor stores them. |
45-
46-
<!--we say later that these are configurable. where? -->
37+
| **OT network sensor** | PCAP files are stored on the OT sensor for up to 90 days, depending on the sensor's storage capacity. <br><br> Maximum size of filtered PCAPs allowed is set by default to 133,120 MB, but configurable in the `filtered.cache.dir.size.megabytes.max` property in the *pcap.properties* file.<br> If you exceed this size, the oldest backed-up file is deleted to accommodate the new one. <br><br> For more information, see [Download PCAP files](how-to-view-alerts.md#download-pcap-files). |
38+
| **On-promises management console** | PCAP files aren't stored on the on-premises management console. <br><br> Access PCAP files from the on-premises management console using a direct link to the sensor, for as long as the on premises sensor stores them. |
4739

4840
## Security recommendation retention
4941

@@ -77,34 +69,28 @@ Only service and processing log files are stored on the Azure portal, and are re
7769

7870
Other OT network monitoring log files are stored only on the OT network sensor and on-premises management console.
7971

80-
On both the OT sensor and the on-premises management console, older log files are overridden when the appliance's storage has reached its maximum capacity. Log file sizes differ depending on the amount of content, but the average size per log file is 100-150 MB. <!--you'd written log here, not log file. I assume it's log file since each indidvidual log would be much, much smaller, no?-->
72+
On both the OT sensor and the on-premises management console, older log files are overridden when the appliance's storage has reached its maximum capacity. Log file sizes differ depending on the amount of content, but the average size per log file is 100-150 MB.
8173

82-
<!-- `There are numerous different kinds of log files, and they have different storage capacities.` Is there other data we're not including here? Why aren't we including it? I think we should if we can. This statement leaves me with questions.-->
83-
84-
<!-- `Some of the logs have rotation and the data isn't overridden immediately.` Not sure what this means? Also, lets avoid words like "some" - which just leaves me with the question of "which"? can we clarify what this means?-->
85-
86-
<!--for more information, see ... what? Maybe the troubleshooting article?-->
74+
For more information, see:
8775

88-
<!--what about log files on the Enterprise IoT sensor? Can you ask Nimrod / Theo?-->
76+
- [Troubleshoot the sensor and on-premises management console](how-to-troubleshoot-the-sensor-and-on-premises-management-console.md).
77+
- [Download a diagnostics log for support](how-to-manage-individual-sensors.md#download-a-diagnostics-log-for-support).
8978

9079
## On-premises backup file capacity
9180

9281
Both the OT network sensor and the on-premises management console have automated backups running daily, which are stored as follows:
9382

9483
| Storage type | Details |
9584
|---------|---------|
96-
| **OT network sensor** | The maximum size of sensor backup files stored on the sensor itself is 100 GB. Older backup files are deleted if the total backup file size passes this limit. <br><br>However, each sensor also has its own, extra backup directory on the on-premises management console. <br><br> For more information, see [Set up backup and restore files](how-to-manage-individual-sensors.md#set-up-backup-and-restore-files). |
97-
| **On-promises management console** | The following types of backup files are stored on the on-premises management console, each with their own maximum file size: <br><br> - **On-premises management console backup file**: Set by default to 10 GB, but configurable in the `backup.max_directory_size.gb` property.<br> - **OT sensor backup files**: Set by default to 40 GB, but configurable in the `sensors_backup.total_size_allowed.gb` property.|
85+
| **OT network sensor** | The maximum size of sensor backup files stored on the sensor itself is set by default to 100 GB, but configurable in the `max_directory_size_in_gb` property in the *backup.properties.configurable* file. <br><br> Older backup files are deleted if the total backup file size passes this limit. <br><br> However, each sensor also has its own, extra backup directory on the on-premises management console. <br><br> For more information, see [Set up backup and restore files](how-to-manage-individual-sensors.md#set-up-backup-and-restore-files). |
86+
| **On-promises management console** | The following types of backup files are stored on the on-premises management console, each with their own maximum file size: <br><br> - **On-premises management console backup file**: Set by default to 10 GB, but configurable in the `backup.max_directory_size.gb` property in the *backup.properties.configurable* file.<br> - **OT sensor backup files**: Set by default to 40 GB, but configurable in the `sensors_backup.total_size_allowed.gb` property in the *backup.properties.configurable* file. <br><br> For more information, see [Set up backup and restore files](how-to-manage-individual-sensors.md#set-up-backup-and-restore-files)|
9887

9988
For more information, see:
10089

10190
- [Configure backup settings for an OT network sensor](how-to-manage-individual-sensors.md#set-up-backup-and-restore-files)
10291
- [Configure OT sensor backup settings from an on-premises management console](how-to-manage-sensors-from-the-on-premises-management-console.md#backup-storage-for-sensors)
10392
- [Configure backup settings for an on-premises management console](how-to-manage-the-on-premises-management-console.md#define-backup-and-restore-settings)
10493

105-
<!--what about backup files on the Enterprise IoT sensor? Can you ask Nimrod / Theo?-->
106-
<!-- these parameter names. we don't mention them anywhere else in the docs. are we sure we want to mention them now? I'd almost prefer to open a separate user story to add how-tos to the docs for how to configure these values, and leave this now as the default only. please check with the SMEs on this one-->
107-
10894
## Next steps
10995

11096
For more information, see:

0 commit comments

Comments
 (0)