Go to the table of contents Go to the previous page Go to the next page
TRITON RiskVision System Management : Configuring RiskVision local storage settings
Configuring RiskVision local storage settings
52034 | System Management | TRITON RiskVision | 24-Sep-2015
Use the System > Local Storage tab to configure how long incident and session data is stored on the RiskVision appliance, and to enable or disable pcap file storage.
Data Retention
You can customize the factors that determine how long incident and session data is stored, and what happens when the database reaches its configured limits.
Use the Incident Storage box to configure:
*
*
*
Enter a new number in the Maximum Records Allowed dialog box.
*
*
To do this, mark or clear the Enable database cleanup check box.
Note that if you disable database cleanup, when the database is full, new records will be discarded. Database cleanup deletes the oldest records to make room for new records.
*
*
Click the number of days next to Delete records older than.
*
*
If the maximum number of incident records is reached before the oldest records reach the obsolescence period that you select, and database cleanup is enabled, the oldest records will still be deleted to make room for newer records.
Likewise, even if the database is not full, records older than the period specified will be deleted by the cleanup job.
Use the Session Storage box to configure:
*
Session data is stored only when the Log all sessions option is enabled on the Diagnostics page. Session logging is generally enabled only for troubleshooting, and disabled when the troubleshooting process is complete.
*
Because session data is typically used for troubleshooting, it is a best practice to allow the automated database cleanup process to remove data that is no longer needed.
*
If you have enabled database cleanup for incident storage, session storage, or both, also set a time to have a database job Perform database cleanup daily (23:30, by default).
Pcap retention
Use the Incident Pcap Retention box to configure:
*
To give you as much data as possible about malicious and suspicious incidents that occur in your network, pcap retention is enabled by default.
*
*
Even with pcap retention enabled, pcap files cannot be created for all incidents. If analysis of a transaction takes more than 5 minutes, the pcap file is discarded before the system determines whether or not an incident has occurred.
Incidents that do not have a corresponding pcap file are still logged, and still appear in the table on the Incidents page.
*
*

Go to the table of contents Go to the previous page Go to the next page
TRITON RiskVision System Management : Configuring RiskVision local storage settings
Copyright 2015 Raytheon | Websense. All rights reserved.