Data generated by the appliance
During monitoring, the appliance produces several categories of data:- Full packet captures. Complete copies of network traffic, stored as packet capture files for detailed forensic review.
- Structured logs. Records of network activity, including protocol-level detail and connection metadata.
- Alerts. Detections raised when observed traffic matches intrusion detection rules.
- File analysis results. Findings from files extracted from the traffic and analyzed.
All data the appliance generates is retained on the appliance until it is either overwritten by newer data or offloaded. Storage and retention are covered on the data storage page.