Data Retention Policy
eyeInspect Passive Sensors implement retention mechanisms to ensure maximum availability of critical data even in case of temporary disconnection from the Command Center. If a Passive Sensor gets disconnected from the Command Center, it retains the following data until the connection is re-established:
- Assets and communications between assets: In case of disconnection from the Command Center, Passive Sensors keep on tracking and retaining up to ten thousand hosts and fifty thousand communication links. These are default configuration parameters, which can be changed if required. Hosts and communications are tracked until they become inactive (in other words, until they are not observed communicating for twenty-four hours) and until the Command Center retrieves their information. Once the Command Center retrieves the information about inactive hosts and links, they are cleared from the Passive Sensor memory.
- Alerts: Alerts are the most critical data in eyeInspect, as they contain
information about potential operational problems and cyber threats. Therefore,
alert retention is limited only by the following constraints on the file
system:
- Minimum amount of disk space to remain free after storing Alerts (default 2Gb)
- Maximum disk percentage to be used for Passive Sensor data (default 90%)
When the Sensor reaches these limits, it starts rotating Alerts instead of adding new ones. It deletes the oldest Alerts to free up some disk space for the new ones.
- Network flows and Events: The amount of network flows and Event logs retained
by Passive Sensors is limited by the following two parameters:
- Maximum buffer size (default 1Gb)
- Maximum number of messages, in specific Events and network flow related logs (default 100000)
Except for Alerts, all data is retained in memory; therefore, a failure of the Passive Sensor would result in the loss of these data. Since the amount of memory on Passive Sensors is limited, the constraints described in this section apply to the amount of data retained.
All of the default parameter values presented above are configurable, but shall be adjusted only after consultation with the Forescout support team.