Red Hand Analytics
Data Source
Review report metadata, capture timeframe, completion details, and data-quality recommendations.Data Source describes the evidence used to create the report and calls out capture conditions that can affect the analysis.
Report metadata
The page can show the original filename, file size, report source, analysis completion time, capture start and end times, and duration. PCAP metadata is retrieved using the report key because it describes the uploaded report rather than its analysis database.
Collector reports identify their source as Collector and may remain online while new data is processed.
Recommendations
Recommendations appear directly below the page title and span the content width. Red Hand Analytics may recommend:
- A fresh capture when the observed traffic is more than 30 days old.
- A longer capture when the timeframe is shorter than one hour.
- Red Hand Collector when continuous observation would provide better evidence than a short snapshot.
Recommendations improve evidence quality; they do not invalidate the current report.
Analysis completion
Analysis Completed uses the report completion timestamp. Not Available means the report metadata did not include a usable completion value, not that analysis necessarily failed.
Report expiration
Temporary and account reports can have different retention periods. My Reports shows the expiration date supplied by the report metadata and warns when a report has less than 72 hours remaining. Dates are stored and compared in UTC, then displayed in the user's local timezone.
Expired reports are removed from My Reports by the server-side report view.
Capture quality
Missing packets, asymmetric visibility, offloaded traffic, encrypted protocols, and short timeframes can all change what the report can conclude. Use the metadata and recommendations when deciding how much confidence to place in an absence of evidence.
See it in context