> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cyberup24.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Data Overview

The LARK automatically collects and processes large volumes of network data during operation. Data handling is automated end to end: as traffic is captured, it is processed, enriched, indexed, and stored without operator action. There are no pipelines to configure or manage; all data handling is configured before the appliance is delivered.

Operator responsibility around data is limited to monitoring storage usage and offloading data to be retained, both covered later in this section.

## Data generated by the appliance

During monitoring, the appliance produces several categories of data:

* **Full packet captures.** Complete copies of network traffic, stored as packet capture files for detailed forensic review.
* **Structured logs.** Records of network activity, including protocol-level detail and connection metadata.
* **Alerts.** Detections raised when observed traffic matches intrusion detection rules.
* **File analysis results.** Findings from files extracted from the traffic and analyzed.

Where optional applications are installed, they may generate additional data. For example, active vulnerability scanning produces reports on the systems it assesses.

<Note>
  All data the appliance generates is retained on the appliance until it is either overwritten by newer data or offloaded. Storage and retention are covered on the data storage page.
</Note>
