Data Retention Policy
    • 29 Aug 2024
    • 1 Minute to read
    • PDF

    Data Retention Policy

    • PDF

    Article summary

    We ingest our customer’s telemetry data into our Amazon Web Services (AWS) S3 Storage. After 14 days, all of the Endpoint Detection and Response (EDR) telemetry that is not related to a threat is moved to our AWS archival storage, where it is currently retained for a total of 90 days.

    Data can be requested by contacting your account team.

    Note: Once the data is moved into the archive, it takes time to recover and recovery can be costly. 

    How is the data in cold storage sent/provided? 

    The data files are provided in JSON format, zipped and can be made available via a secure, private link.

    What do we need to do to load/review the data? Do we have to stand up some kind of special environment for that?

    The contents of the file(s) that are extracted should be able to be opened/reviewed with any text editor or JSON parser.

    Could we leverage Azure Sentinel to import and review the JSON data? What other tools can they use for this?

    You can use any sort of JSON data parser you choose. Using Canary Exporter would be a great alternative for this, especially if things are time sensitive (quicker option). The downsides are bandwidth and storage.

    How are Endpoints, Alerts, and Events handled?

    For details on how Red Canary handles Endpoints, Alerts, and Events, see the table below:

    Data type

    Default  Policy

    Endpoints

    Endpoints associated with an Alert, Event, or Threat are displayed indefinitely. All other endpoints are displayed until their last check-in and last activity time exceeds one year. Learn more about Endpoints.

    Alerts

    Alerts associated with a tipoff or an event are retained indefinitely. External alerts not associated with an event are retained for 90 days. For more information, review our Alerts Lifecycle.

    Events

    Events associated with a confirmed threat are retained indefinitely. Other events are retained for one year. For more information, review our Event Lifecycle.

     


    Was this article helpful?