- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-15-2025 07:45 AM
Hello All,
Can anyone explain as to why a dataset that is a subset of the xdr_data dataset may have a total days stored value less than the xdr_data dataset?
In my case the total days stored of the login_logs dataset is less than that of the parent dataset xdr_data:
This is not a new configuration, so I am curious as to why there is a difference between the two.
The hot storage license for the tenant is:
Cheers
07-17-2025 06:28 AM
Hi Nohash4u,
The logins_log dataset incorporates login logs from xdr agent and other login logs from other products (Global Protect VPN, Firewall....),
XDR_dataset has much more types of different events.
According with what I see in the pic you sent, I see that login_logs dataset has data from 22nd Jun to 12th Jul which means that there was no login events captured before and after those dates respectively
Same explanation from xdr_dataset, which contains much more types of events so different types of events than logins were captured before and after the login events in the previous dataset.
If you believe that some login logs might have been missed or lost, please feel free to open a TAC support case to investigate it further.
Does it make sense ?
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.
KR,
Luis
07-17-2025 06:28 AM
Hi Nohash4u,
The logins_log dataset incorporates login logs from xdr agent and other login logs from other products (Global Protect VPN, Firewall....),
XDR_dataset has much more types of different events.
According with what I see in the pic you sent, I see that login_logs dataset has data from 22nd Jun to 12th Jul which means that there was no login events captured before and after those dates respectively
Same explanation from xdr_dataset, which contains much more types of events so different types of events than logins were captured before and after the login events in the previous dataset.
If you believe that some login logs might have been missed or lost, please feel free to open a TAC support case to investigate it further.
Does it make sense ?
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.
KR,
Luis
07-21-2025 07:20 AM
Thanks @eluis for clarifying! The login_logs dataset continues to increase to the hot retention period of 31 total days stored. I am unsure if there was a problem with the capturing of such login events, or if the other possibility of no one logging in for a period of time occurred. I will post back here with any new findings.
Cheers!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!