- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-14-2022 06:14 AM
Hello-
Does anyone know the following details to how the product manages the retention for logs and quarantine?
I understand you can set the log quota to a specific size. This will leverage that on local disk. What I am not clear on are the following items.
What types of log data are included in this quota (some or all)?
How does the product "clean up" after itself? Is it possible the local disk could become full and I would have to manually clean up or is there a mechanism to perform this maintenance automatically?
How about the quarantine folder? Same type of question. Does it clean up automatically or require manual intervention to remove the files/logs?
Thanks in advance for sharing of your knowledge.
06-15-2022 07:47 PM
HI @Marc_Denman
For your first question, you can refer to the documentation here which lists the data that is collected by XDR.
For your 2nd and 3rd question, they have been addressed earlier here.
To add on to the response in 3rd question: the reasoning behind quarantining is to typically isolate a file and block it from being executed on the endpoints. This gives the investigation team the time to conduct their analysis to determine whether the file is benign or malicious. If the file is benign, you can manually "un-quarantine" the file. Else, the file should be removed from the endpoint as per your organization's information security policies. XDR does not delete a file from the endpoint even after quarantining as it might affect business processes etc.
06-15-2022 07:47 PM
HI @Marc_Denman
For your first question, you can refer to the documentation here which lists the data that is collected by XDR.
For your 2nd and 3rd question, they have been addressed earlier here.
To add on to the response in 3rd question: the reasoning behind quarantining is to typically isolate a file and block it from being executed on the endpoints. This gives the investigation team the time to conduct their analysis to determine whether the file is benign or malicious. If the file is benign, you can manually "un-quarantine" the file. Else, the file should be removed from the endpoint as per your organization's information security policies. XDR does not delete a file from the endpoint even after quarantining as it might affect business processes etc.
08-30-2024 12:07 AM - edited 08-30-2024 12:08 AM
Hi @bbarmanroy,
Next question is: how?
In the File Quarantine Details list, or in the Incident/Alert View with a right click, there is only Restore but no (Permanently) Delete.
It is not easy directly on the enpoint as well. As the file is naturally moved from its original folder and renamed with random numbers in quarantine folder, how can one know which file is the right one?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!