How far back
do you need to see?
Retention is the question that decides whether continuous capture is a capability or an expensive habit. It is arithmetic, and it is worth doing before anyone quotes you a figure.
Storage for continuous capture is average utilised throughput multiplied by retention time — not link speed multiplied by retention time. The distinction is the whole cost model: a 1 Gbps link averaging 8% needs roughly a tenth of what its nameplate suggests. As a working figure, 100 Mbps of sustained real traffic is about 1 TB per day, before any trimming. The right retention is set by the questions you need to answer — days for performance troubleshooting, weeks to months for security investigation.
What actually drives the number.
Average utilisation, not link speed
Sizing from the nameplate rate overstates the requirement by an order of magnitude on most enterprise links. Take real busy-hour and daily-average figures from your own interface statistics.
The number you want is already in your SNMP history. Use a month of it, not a peak.
A working conversion
100 Mbps sustained is about 1.08 TB per day. 1 Gbps sustained is about 10.8 TB per day. Multiply by your real average, not your capacity, and by the number of capture points.
Do this per capture point and add them up. A single figure for "the network" is always wrong.
Slicing, if the payload is not the point
Keeping only headers cuts storage dramatically while preserving timing, sequence, retransmissions, handshakes and every conversation. It rules out content inspection later, which is a real trade.
Full packets for security work; headers are often enough for performance work.
Filtering what you never look at
Excluding backup replication or storage traffic can halve the volume. It also guarantees you cannot investigate those flows, and they are exactly the flows that cause microbursts.
Filter deliberately and write down what you excluded. An undocumented filter becomes a mystery gap.
Tiering by age
Recent capture on fast storage, older capture on cheaper storage. Investigations are overwhelmingly about the last few days; the older data mostly needs to exist rather than be fast.
This is usually where a retention target that looked unaffordable becomes affordable.
The retention you need is set by the question
Performance troubleshooting is answered by days. Compliance and dispute questions arrive in weeks. Security investigation frequently reaches back months, because that is how long an intrusion can sit before anyone notices.
Pick the longest question you genuinely need to answer, then size for it honestly.
Four steps to a real number.
- 1
Pull a month of real throughput per capture point
Daily average and busy hour. This is already in your interface history and takes minutes to extract.
- 2
Multiply out to raw daily volume
Average throughput times 86,400 seconds. Do it per point and sum. This is the honest starting number.
- 3
Decide what you can trim, and record it
Slicing and filtering both cut the number and both cut what you can investigate. Trading them away silently is how a capture becomes useless at the worst moment.
- 4
Set retention from the longest question you must answer
Then check the result against the budget. If it does not fit, shorten retention deliberately rather than discovering the limit during an incident.
How Net-Monitor handles this
- Sizing is done per deployment, from your traffic. There is no published retention figure because a figure that ignores your link rates would be meaningless.
- Historical search is what makes retention worth paying for. Storage you cannot query by host, interface, protocol or conversation is an archive, not a capability.
- The capture is analysed online as it is written. You are not paying for storage in the hope of using it later; the same data is producing detections continuously.
Short answers.
How much storage does continuous packet capture need?
Multiply average utilised throughput by retention time. As a working figure, 100 Mbps of sustained real traffic is roughly 1 TB per day. The common mistake is sizing from link speed rather than actual utilisation, which overstates the requirement by around ten times on a typical enterprise link.
How long should packet captures be kept?
It depends on the question you need to answer. Performance troubleshooting is usually satisfied by a few days. Compliance and supplier disputes tend to arrive within weeks. Security investigation often needs months, because intrusions are frequently discovered long after they began.
Can I reduce storage by keeping only headers?
Yes, and it saves a great deal. Headers preserve timing, sequence numbers, retransmissions, handshakes, and every conversation with its size and duration — which covers nearly all performance work. What you give up is any later inspection of content, which matters for some security investigations.
Is it worth capturing at 10 Gbps?
It depends on how much of that 10 Gbps is actually used and what you need to keep. Many 10G links average well under 10%, which makes the arithmetic far more reasonable than the headline rate suggests. Working from real utilisation is the difference between an affordable project and one that gets cancelled.
Related questions.
Want the number for your network?
Bring a month of interface statistics and we will size it with you honestly, including where it does not fit.