This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Discussions
Announcement Banner

Users are unable to open Netwitness Support Cases via email. Please open support cases via portal or by phone

View Details
  • NetWitness Community
  • Discussions
  • Re: Archiver Storage
  • Options
    • Subscribe to RSS Feed
    • Mark Topic as New
    • Mark Topic as Read
    • Float this Topic for Current User
    • Bookmark
    • Subscribe
    • Mute
    • Printer Friendly Page

Archiver Storage

VishamRawat
VishamRawat Beginner
Beginner
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

‎2019-07-25 10:07 AM

#

Okay, maybe I'm not getting the whole picture here, but I'm wondering what exactly is sent to the Archiver from the Decoders.

 

 

 

For example.

 

I have 3.5 TB of Archiver storage. And this has been designed for 9 months of hot storage. Additionally, the Log Decoder has an ingestion rate of 150GB per day. This means 3.5 TB in about 20-25 days.

 

Now, as per my understanding, the Archiver is sent a copy of all raw logs (and meta generated on the Log Decoder). So, shouldn't the Archiver be full and start rolling over logs in less than a month? Yet, the oldest meta file I see if of December? How is this possible? Or is it that not all data from the Log Decoder is sent to the Archiver?

  • Archiver
  • Community Thread
  • Decoder
  • Discussion
  • Forum Thread
  • Log Decoder
  • netwiness
  • NetWitness
  • NW
  • NWP
  • RSA NetWitness
  • RSA NetWitness Platform
  • rsasa
  • Storage
0 Likes
Share
Reply
  • All forum topics
  • Previous Topic
  • Next Topic
3 REPLIES 3

GuyWilliams
Employee GuyWilliams
Employee
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

‎2019-07-25 10:14 AM

Hi Visham,

 

The data on the Archiver is compressed by default as it is for long term storage and not investigation.

 

Thanks,

Guy

1 Like
Share
Reply

VishamRawat
VishamRawat Beginner
Beginner
In response to GuyWilliams
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

‎2019-07-25 11:19 AM

Thanks Guy. Completely missed that. Just another quick query. I've recently seen the Duration on the Archiver Hot Storage change from 9 months to 8 months. Does this mean, that the volume of logs streaming into the Archiver has increased, resulting in the rollover of a substantial volume of older logs?

0 Likes
Share
Reply

GuyWilliams
Employee GuyWilliams
Employee
In response to VishamRawat
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

‎2019-07-25 11:53 AM

Yes, that's most likely the case.  Either more logs or bigger logs came in. 

 

The Archiver saves the logs in database slices.  Once the disk usage exceeds 95% the oldest slices are removed to bring it below 95% usage.

 

You can configure warm (still online) or cold (offline, inaccessible) storage to roll the older slices over to.

2 Likes
Share
Reply
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.