Kaspersky Anti Targeted Attack Platform

Managing traffic saving settings

The application can save traffic received at the time when an event was registered. Traffic is saved in the database of the Central Node server when registering events for which traffic saving is enabled. The application can also directly save traffic in the server database upon a traffic download request, using temporary traffic dump files.

The application stores traffic data in blocks. If a block of traffic is associated with multiple events (for events recorded within a short period of time), such a block of traffic is not duplicated in the database.

To manage the settings for saving traffic in the server database:

  1. Select the Sensor servers section in the window of the application web interface.
  2. Click the card of the relevant Central Node component.

    This opens a window with information about the component.

  3. Click Edit.
  4. Go to the General tab.
  5. Under Traffic for events, specify the maximum volume of traffic to be saved in the Max volume field.

    You can select the unit of measure for the size limit: MB or GB.

    When editing the value, you also need to take into account that the sum total of all size limits may not exceed the specified maximum storage capacity for the server.

  6. Click Save.

Traffic saving settings are modified.