# Track a Network Watcher capture file beyond the capture resource

> The capture session, its resource and its stored file have different completion and deletion behavior.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-287-track-a-network-watcher-capture-file-beyond-the-capture-resource/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:27:09+00:00
- Modified: 2026-09-10T01:23:49+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

The capture session, its resource and its stored file have different completion and deletion behavior.

## Potentially affected

Azure Network Watcher packet captures stored in Azure Storage, on a target VM, or both.

## DSE recommendation

Record each capture-file destination and manage its retention separately from the Network Watcher resource.

## Article

## Source facts

A completed Network Watcher packet capture can be stored in Azure Storage, on the target VM, or in both locations selected at creation. For a capture written to Azure Storage, the file may remain in a temporary location and appear in the storage account container only after the session completes.

Deleting the packet-capture resource in Network Watcher does not delete the file from either the storage account or VM. Microsoft requires separate file deletion when that captured data is no longer needed. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/network-watcher/packet-capture-manage).

## Applicability

Identify the target, configured destinations and authorized investigation before handling a capture. For Azure Storage, keep a running session’s temporary output distinct from a finalized evidence file.

## DSE recommendation

DSE recommends a capture register that records where every copy is expected and who controls its retention. Preserve required evidence before authorizing cleanup. Do not close a data-removal task merely because the capture no longer appears in Network Watcher. Conversely, do not conclude that collection failed solely because an active session’s Azure Storage file is not yet visible in its final container.

## Verification

After the session completes, verify the expected file in each configured destination and confirm it contains the authorized test traffic. For an approved cleanup, check the actual files separately from the capture resource. Retain the observed outcome and any remaining copy as an explicit follow-up item. Do not remove investigation material until its owner has confirmed that retention requirements are satisfied.

## Official references

[Microsoft Learn: Manage Packet Captures](https://learn.microsoft.com/en-us/azure/network-watcher/packet-capture-manage). Source retrieved September 9, 2026.

## Primary reference

- Name: Manage Packet Captures - Azure Network Watcher | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/network-watcher/packet-capture-manage
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Track a Network Watcher capture file beyond the capture resource,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-287-track-a-network-watcher-capture-file-beyond-the-capture-resource/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
