Enable Dataset Storage Retention

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Enable Dataset Storage Retention

How does one determine what datasets are stored in Hot Storage? 

 

I understand that a Hot Storage License dictates the length that data is retained, but what about determining what datasets retain data to begin with? 

 

For example

RChristie699701_0-1723572296760.png

RChristie699701_1-1723572324013.png

RChristie699701_2-1723572389430.png

 

Furthermore, I am confused as to why the 'Last Updated' column is populated, and the 'Total Days Stored' column is not. 

 

Any insight is greatly appreciated. Cheers. 

2 REPLIES 2

L4 Transporter

Hello @R.Christie699701 ,

 

Thanks for reaching out on LiveCommunity.

With a regular Cortex XDR license, the data is automatically sent to hot storage for the default retention period according to the license, typically 1 month. If you've purchased additional retention add-ons to extend the hot storage, this is added in monthly increments to the hot storage duration according to the license. For example, a Period-Based Retention - Hot Storage license enables you to extend all the data(All datasets according to your base license pro per endpoint/pro per GB) in hot storage for the number of months designated, while an Additional Hot Storage license provides flexible hot storage so you can extend only the data collected in specific datasets for the number of months designated. 

So you can only choose between datasets when you have additional hot storage license.

 

Total days stored may not be relevant because the storage database is a snapshot based database hence it stores all relevant data in a given time.

 

Please click Accept as Solution to acknowledge that the answer to your question has been provided.

Hi @nsinghvirk

 

Thank you for your response! 

I believe I am now able to wrap my head around licenses, and what gives you the ability to select which datasets are stored. 

 

To clarify the difference between the 'Last Updated' and 'Total Days Stored' columns:

  • 'Last Updated' indicates the last time the dataset was refreshed and checked for new data. 
  • 'Total Days Stored'  may be empty because there is no data to populate the dataset. If there is data inside this dataset, then the field will be populated with the number of days the data is stored since it was captured. The field will increment by one each day and stop at the maximum as dictated by retention period which is in turn decided by the Cortex XDR license. 

Is this correct? 

 

Cheers

  • 137 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!