{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-287-track-a-network-watcher-capture-file-beyond-the-capture-resource/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-287-track-a-network-watcher-capture-file-beyond-the-capture-resource/",
        "slug": "dse-20260909-287-track-a-network-watcher-capture-file-beyond-the-capture-resource",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-287-track-a-network-watcher-capture-file-beyond-the-capture-resource/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-287-track-a-network-watcher-capture-file-beyond-the-capture-resource.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-287-track-a-network-watcher-capture-file-beyond-the-capture-resource/"
        },
        "title": "Track a Network Watcher capture file beyond the capture resource",
        "summary": "The capture session, its resource and its stored file have different completion and deletion behavior.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:27:09+00:00",
        "modified_at": "2026-09-10T01:23:49+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 250,
        "potentially_affected": "Azure Network Watcher packet captures stored in Azure Storage, on a target VM, or both.",
        "dse_recommendation": "Record each capture-file destination and manage its retention separately from the Network Watcher resource.",
        "primary_source": {
            "name": "Manage Packet Captures - Azure Network Watcher | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/network-watcher/packet-capture-manage",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>A completed Network Watcher packet capture can be stored in Azure Storage, on the target VM, or in both locations selected at creation. For a capture written to Azure Storage, the file may remain in a temporary location and appear in the storage account container only after the session completes.</p>\n<p>Deleting the packet-capture resource in Network Watcher does not delete the file from either the storage account or VM. Microsoft requires separate file deletion when that captured data is no longer needed. <a href=\"https://learn.microsoft.com/en-us/azure/network-watcher/packet-capture-manage\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the target, configured destinations and authorized investigation before handling a capture. For Azure Storage, keep a running session&#8217;s temporary output distinct from a finalized evidence file.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends a capture register that records where every copy is expected and who controls its retention. Preserve required evidence before authorizing cleanup. Do not close a data-removal task merely because the capture no longer appears in Network Watcher. Conversely, do not conclude that collection failed solely because an active session&#8217;s Azure Storage file is not yet visible in its final container.</p>\n<h2>Verification</h2>\n<p>After the session completes, verify the expected file in each configured destination and confirm it contains the authorized test traffic. For an approved cleanup, check the actual files separately from the capture resource. Retain the observed outcome and any remaining copy as an explicit follow-up item. Do not remove investigation material until its owner has confirmed that retention requirements are satisfied.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/network-watcher/packet-capture-manage\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Manage Packet Captures</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nA completed Network Watcher packet capture can be stored in Azure Storage, on the target VM, or in both locations selected at creation. For a capture written to Azure Storage, the file may remain in a temporary location and appear in the storage account container only after the session completes.\nDeleting the packet-capture resource in Network Watcher does not delete the file from either the storage account or VM. Microsoft requires separate file deletion when that captured data is no longer needed. Microsoft Learn.\nApplicability\nIdentify the target, configured destinations and authorized investigation before handling a capture. For Azure Storage, keep a running session’s temporary output distinct from a finalized evidence file.\nDSE recommendation\nDSE recommends a capture register that records where every copy is expected and who controls its retention. Preserve required evidence before authorizing cleanup. Do not close a data-removal task merely because the capture no longer appears in Network Watcher. Conversely, do not conclude that collection failed solely because an active session’s Azure Storage file is not yet visible in its final container.\nVerification\nAfter the session completes, verify the expected file in each configured destination and confirm it contains the authorized test traffic. For an approved cleanup, check the actual files separately from the capture resource. Retain the observed outcome and any remaining copy as an explicit follow-up item. Do not remove investigation material until its owner has confirmed that retention requirements are satisfied.\nOfficial references\nMicrosoft Learn: Manage Packet Captures. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nA completed Network Watcher packet capture can be stored in Azure Storage, on the target VM, or in both locations selected at creation. For a capture written to Azure Storage, the file may remain in a temporary location and appear in the storage account container only after the session completes.\n\nDeleting the packet-capture resource in Network Watcher does not delete the file from either the storage account or VM. Microsoft requires separate file deletion when that captured data is no longer needed. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/network-watcher/packet-capture-manage).\n\n## Applicability\n\nIdentify the target, configured destinations and authorized investigation before handling a capture. For Azure Storage, keep a running session’s temporary output distinct from a finalized evidence file.\n\n## DSE recommendation\n\nDSE recommends a capture register that records where every copy is expected and who controls its retention. Preserve required evidence before authorizing cleanup. Do not close a data-removal task merely because the capture no longer appears in Network Watcher. Conversely, do not conclude that collection failed solely because an active session’s Azure Storage file is not yet visible in its final container.\n\n## Verification\n\nAfter the session completes, verify the expected file in each configured destination and confirm it contains the authorized test traffic. For an approved cleanup, check the actual files separately from the capture resource. Retain the observed outcome and any remaining copy as an explicit follow-up item. Do not remove investigation material until its owner has confirmed that retention requirements are satisfied.\n\n## Official references\n\n[Microsoft Learn: Manage Packet Captures](https://learn.microsoft.com/en-us/azure/network-watcher/packet-capture-manage). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-287-track-a-network-watcher-capture-file-beyond-the-capture-resource/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-287-track-a-network-watcher-capture-file-beyond-the-capture-resource/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-287-track-a-network-watcher-capture-file-beyond-the-capture-resource/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Track a Network Watcher capture file beyond the capture resource",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-287-track-a-network-watcher-capture-file-beyond-the-capture-resource/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-287-track-a-network-watcher-capture-file-beyond-the-capture-resource/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-287-track-a-network-watcher-capture-file-beyond-the-capture-resource/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-287-track-a-network-watcher-capture-file-beyond-the-capture-resource/",
                "headline": "Track a Network Watcher capture file beyond the capture resource",
                "description": "The capture session, its resource and its stored file have different completion and deletion behavior.",
                "abstract": "The capture session, its resource and its stored file have different completion and deletion behavior.",
                "articleBody": "Source facts\nA completed Network Watcher packet capture can be stored in Azure Storage, on the target VM, or in both locations selected at creation. For a capture written to Azure Storage, the file may remain in a temporary location and appear in the storage account container only after the session completes.\nDeleting the packet-capture resource in Network Watcher does not delete the file from either the storage account or VM. Microsoft requires separate file deletion when that captured data is no longer needed. Microsoft Learn.\nApplicability\nIdentify the target, configured destinations and authorized investigation before handling a capture. For Azure Storage, keep a running session’s temporary output distinct from a finalized evidence file.\nDSE recommendation\nDSE recommends a capture register that records where every copy is expected and who controls its retention. Preserve required evidence before authorizing cleanup. Do not close a data-removal task merely because the capture no longer appears in Network Watcher. Conversely, do not conclude that collection failed solely because an active session’s Azure Storage file is not yet visible in its final container.\nVerification\nAfter the session completes, verify the expected file in each configured destination and confirm it contains the authorized test traffic. For an approved cleanup, check the actual files separately from the capture resource. Retain the observed outcome and any remaining copy as an explicit follow-up item. Do not remove investigation material until its owner has confirmed that retention requirements are satisfied.\nOfficial references\nMicrosoft Learn: Manage Packet Captures. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:27:09+00:00",
                "dateModified": "2026-09-10T01:23:49+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-287-track-a-network-watcher-capture-file-beyond-the-capture-resource/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-287-track-a-network-watcher-capture-file-beyond-the-capture-resource/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Track a Network Watcher capture file beyond the capture resource"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 250,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Manage Packet Captures - Azure Network Watcher | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/network-watcher/packet-capture-manage"
                }
            }
        ]
    }
}