Skip to main content
Migration Notice
We're migrating documentation from the old portal into this one. Some things may look a little different or out of place in the meantime — we know, and we're working to get it right. If something's unclear or doesn't look right, let us know.
Version: 2.15.0

Investigate & Recover — Snapshots Tab

Introduction

The Snapshots tab, on the Investigate & Recover page for a Threat Detections event, lists all snapshots associated with the event on every SMB share the affected user had access to, across all managed clusters.

Each entry shows a Snapshot ID, Path, Device, Date Created, and Expiry column. Snapshots default to a 48-hour expiry after creation.

Snapshots may be reused from an earlier event, not newly created

As of 2.15.0, the system avoids creating a redundant snapshot on a share if one was already taken recently (within a configurable reuse window) — for example, by an earlier event affecting the same share. In that case, the entry shown here reflects the original snapshot's creation time, not the time this particular event was detected, so Date Created and Expiry can predate the event you're viewing. This also means two events close together in time on the same share may point to the very same snapshot.

If a snapshot is deleted manually from OneFS while it's still inside that reuse window, the system can continue to treat it as available and skip creating a replacement — so a new event may show no snapshot for that share, with no explicit error. If you expect a snapshot and don't see one, check whether it (or an earlier one on the same path) was deleted directly on the cluster.

Snapshot budget and retention behavior are configured separately — see Snapshot Settings.

Using This Tab

Use the Snapshots tab to:

  • Verify that snapshots were successfully created for the shares you expect.
  • Identify any shares where snapshot creation failed (shown with an error indicator).
  • Access snapshots for manual recovery operations outside this interface if needed.

This tab is distinct from Recovery Manager's snapshot-based file recovery on the Items & Recovery tab — Recovery Manager selects and applies snapshots automatically per file, while this tab gives you a direct view of every snapshot the event triggered.

See also