You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/references-data-retention.md
+53-14Lines changed: 53 additions & 14 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,7 +2,7 @@
2
2
title: Data retention across Microsoft Defender for IoT
3
3
description: Learn about the data retention periods and capacities for Microsoft Defender for IoT data stored in Azure, the OT sensor, and on-premises management console.
4
4
ms.topic: reference
5
-
ms.date: 12/26/2022
5
+
ms.date: 01/22/2023
6
6
---
7
7
8
8
# Data retention across Microsoft Defender for IoT
@@ -38,9 +38,26 @@ The following table lists how long PCAP data is stored in each Defender for IoT
38
38
| Storage type | Details |
39
39
|---------|---------|
40
40
|**Azure portal**| PCAP files are available for download from the Azure portal for as long as the OT network sensor stores them. <br><br> Once downloaded, the files are cached on the Azure portal for 48 hours. <br><br> For more information, see [Access alert PCAP data](how-to-manage-cloud-alerts.md#access-alert-pcap-data). |
41
-
|**OT network sensor**|90 days, depending on the sensor's storage capacity. <br><br> The maximum size of PCAP file storage is set by default to 133,120 MB. If a sensor exceeds this size, the oldest PCAP file is deleted to accommodate the new one. <br><br> For more information, see [Access alert PCAP data](how-to-view-alerts.md#access-alert-pcap-data). |
41
+
|**OT network sensor**|Dependent on [the sensor's storage capacity](#sensor-storage-capacity-by-hardware-profile). <br><br> If a sensor exceeds its maximum storage capacity, the oldest PCAP file is deleted to accommodate the new one. <br><br> For more information, see [Access alert PCAP data](how-to-view-alerts.md#access-alert-pcap-data). |
42
42
|**On-promises management console**| PCAP files aren't stored on the on-premises management console and are only accessed from the on-premises management console via a direct link to the OT sensor. |
43
43
44
+
The utilization of available PCAP storage space depends on factors such as the number of alerts, the type of the alert, and the network bandwidth, all of which affect the size of the PCAP file.
45
+
46
+
> [!TIP]
47
+
> Use external storage to back up PCAP data without dependency on the sensor's storage capacity.
Defender for IoT security recommendations are stored only on the Azure portal, for 90 days from when the recommendation is first detected.
@@ -57,13 +74,13 @@ The following table lists the maximum number of events that can be stored for ea
57
74
58
75
| Hardware profile | Number of events |
59
76
|---------|---------|
60
-
| C5600 | 10M events |
61
-
| E1800 | 10M events |
62
-
| E1000 | 6M events |
63
-
| E500 | 6M events |
64
-
| L500 | 3M events |
65
-
| L100 | 500-K events |
66
-
| L60 | 500-K events |
77
+
|**C5600**| 10M events |
78
+
|**E1800**| 10M events |
79
+
|**E1000**| 6M events |
80
+
|**E500**| 6M events |
81
+
|**L500**| 3M events |
82
+
|**L100**| 500-K events |
83
+
|**L60**| 500-K events |
67
84
68
85
For more information, see [Track sensor activity](how-to-track-sensor-activity.md).
69
86
@@ -75,6 +92,11 @@ Other OT monitoring log files are stored only on the OT network sensor and the o
75
92
76
93
On both OT sensors and the on-premises management console, files are stored for as long as there's available storage space. When the appliance's storage capacity reaches its maximum, the oldest log files are deleted to make room for the new ones.
77
94
95
+
Logs are stored in two different ways:
96
+
97
+
- Logs are saved on one file where the oldest content is overridden when the file reaches it's maximum size
98
+
- Logs are saved on a number of files, and once the number of files reaches the maximum, the oldest file is deleted.
99
+
78
100
Log files sizes differ depending on the amount of content, but the average size per log file is 100-150 MB.
79
101
80
102
For more information, see:
@@ -88,14 +110,31 @@ Both the OT network sensor and the on-premises management console have automated
88
110
89
111
On both the OT sensor and the on-premises management console, older backup files are overridden when the configured storage capacity has reached its maximum.
90
112
91
-
For more information, see [Set up backup and restore files](how-to-manage-individual-sensors.md#set-up-backup-and-restore-files).
113
+
For more information, see [Set up backup and restore files](how-to-manage-individual-sensors.md#set-up-backup-and-restore-files).
92
114
93
-
The following table describes the default maximum sizes for each storage location.
115
+
**Backups on the OT network sensor:**
94
116
95
-
| Storage type | Details |
117
+
The retention of backup files is dependent on the OT network sensor's architecture, where each type of device has a set amount of hard disk space allocated for backup history:
118
+
119
+
| Type of device | Allocated hard disk space |
96
120
|---------|---------|
97
-
|**OT network sensor**| The default maximum size of backup files stored on the OT sensor is 100 GB. If you're using an on-premises management console, each connected OT sensor also has its own, extra backup directory on the on-premises management console. |
98
-
|**On-promises management console**| The default maximum size of backup files stored on an on-premises management console is: <br><br>- **On-premises management console backup file**: 10 GB <br> - **OT sensor backup files**, for any connected OT sensor: 40 GB.|
121
+
|**Laptop**| 0 |
122
+
|**Rugged**| 0 |
123
+
|**Medium**| 20 GB |
124
+
|**Small prod**| 60 GB |
125
+
|**Prod**| 100 GB |
126
+
|**Core**| 100 GB |
127
+
128
+
If the device has 0 allocated hard disk space, then only the last backup will be saved.
129
+
130
+
**Backups on the on-premises management console:**
131
+
132
+
Allocated hard disk space for on-premises management console backup files is limited to 10 GB and to only 20 backups.
133
+
134
+
If you're using an on-premises management console, each connected OT sensor also has its own, extra backup directory on the on-premises management console:
135
+
136
+
- A single sensor backup file is limited to a maximum of 40 GB. If the size of the file exceeds that, it won't be sent to the on-premises management console.
137
+
- Total hard disk space allocated to sensor backup from all sensors on the on-premises management console is 100 GB.
0 commit comments