For a DAS incident review, preserve the alarm record, relevant sensing data where available, route mapping, active configuration and associated video with their timestamps and identifiers. Keep enough context to explain what the system observed and how operators responded. A screenshot of one alarm can be useful, but it rarely provides a complete account of the event.
A distributed acoustic sensing system can form one part of a wider security evidence chain. The retention plan should reflect the records the delivered system actually produces. Use this operational checklist alongside the retention requirements approved for your own site.
Which Parts of a DAS Incident Need Reconstruction?
Start with the review questions rather than selecting files by convenience. Investigators may need to know where the alarm originated, what signal or classification supported it and whether the intended notification reached the control room. Operations staff may also need to explain acknowledgment, verification and escalation decisions.
The available evidence should distinguish an event that was not detected from an alarm that was generated but not delivered or acted upon. Locating the failure within sensing, message delivery or operator handling determines where the investigation should continue. Keeping only the final operator screen can make the distinction impossible.
- Which physical section and optical interval were involved?
- What event did the sensing system report?
- Which configuration governed the decision?
- When did each relevant system receive or display the alarm?
- Which camera view and archive interval were reviewed?
- What did operators record and who accepted responsibility?
Some questions may remain unanswered because the product does not retain the required data. Record those limitations during design and acceptance. Do not promise retrospective signal analysis from an installation that stores only event summaries.

Which DAS Records Should Be Preserved?
Preserve the original event identifiers, timestamps, location fields and event status history supported by the system. Include diagnostic or sensing exports where they are available and relevant. The exact file types and retention capabilities must be confirmed with the supplier.
A processed vibration display, a classifier result and raw optical data are different evidence products. They may have very different storage requirements and interpretation needs. Describe the exported material accurately instead of labeling every waveform as raw data.
| Record | Purpose | Context to Retain |
| Alarm export | Identify the reported event | Identifier, time basis, location and lifecycle |
| Sensing data | Review the available signal evidence | Format, processing and acquisition settings |
| Route map | Connect optical distance to the site | Revision valid at the event time |
| Configuration | Explain the active detection behavior | Version and approved changes |
| Operator history | Reconstruct the response | User actions and associated notes |
Preserve the configuration that applied when the event occurred, not only the latest configuration available during the investigation. Later tuning can change how the same data would be interpreted. Historical route mapping is equally important after cable repair or rerouting.
How Should Video Be Linked to the Alarm?
Use the alarm identifier, camera identity and an unambiguous time interval to connect the records. Retain enough pre-event and post-event footage for the review objective. The interval should be agreed for the site’s operations rather than copied from an unrelated installation.
The guide to DAS integration with video and maps provides the wider context. Evidence retention must verify that the integration can retrieve the relevant historical footage, not just display a live camera. Record any missing footage or known clock offset rather than silently substituting another interval.
Can a Screen Recording Replace the Original Export?
A screen recording can show what an operator saw, but it may omit metadata, frames or original timing information. Keep the supported native export where the review requires it and the system provides it. Use a viewing copy for convenience while preserving the original material under the site’s evidence procedure.
Document any conversion used to make files readable. A converted clip may be useful for discussion without preserving all properties of the original. The review record should make that relationship clear.
How Long Should Routine Records Be Kept?
Set retention periods through the organization’s operational, contractual and applicable legal requirements. Consider how long it usually takes to discover an incident and request the relevant records. A retention window shorter than that delay can remove useful evidence before anyone knows it is needed.
Different record types may justify different periods and storage methods. Event summaries can be relatively compact, while continuous high-detail sensing or video data can be substantial. Confirm actual export rates and retention behavior using the intended configuration.
Distinguish routine rolling retention from preservation of a specific incident. Once a relevant event is identified, the responsible team should follow the approved process for protecting its records from ordinary expiry. That process needs a named owner and a way to confirm completion.
How Can Storage Requirements Be Estimated?
Use measured data rates or documented supplier figures for the selected record types, then apply the intended retention interval and operational overhead. Include indexes, metadata, replication and any required reserve capacity. A generic bytes-per-kilometer estimate can be misleading when acquisition and processing settings differ.
For event-based retention, evaluate the expected event volume and the duration of each retained segment. Include nuisance events and maintenance tests in the estimate where they are stored. A quiet demonstration period may understate the demands of an operating site.
- List each record stream and its retention rule.
- Measure or confirm its rate under the proposed settings.
- Include the expected number and duration of event segments.
- Account for copies, indexes and working space.
- Define capacity warnings and the response owner.
- Test what happens when the storage limit is approached.
Ask whether the system overwrites old records, stops recording or produces a fault when capacity becomes constrained. Those behaviors have different consequences. Monitoring storage health belongs in the operating plan.
What Should an Incident Export Package Contain?
Use a manifest that identifies the event, the files included and the method used to obtain them. Record who exported the material, when the export occurred and which system supplied it. Keep known gaps and timing limitations alongside the files.
Where the organization’s procedure uses file hashes or controlled storage, apply those methods consistently to detect unintended changes. A hash does not establish that a sensor interpretation was correct; it supports a narrower statement about file consistency. Preserve the distinction between integrity of the files and accuracy of their contents.
- Record the incident and alarm identifiers.
- Preserve the relevant original exports.
- Attach the applicable route and configuration revisions.
- Identify associated camera files and time offsets.
- Include operator notes and response history.
- List export tools, conversions and known omissions.
- Store the package through the approved controlled process.

How Can Retention Be Tested Before an Incident?
Run a controlled event and ask a different authorized person to retrieve the complete package later using the normal workflow. This tests discoverability as well as recording. A record that exists but cannot be found by the responsible team may provide little operational value.
For centralized alarm management, confirm the available search, history and export functions in the delivered configuration. Use the acceptance-testing framework to document the retrieval demonstration. Include the time required and any manual steps.
If the review exposes missing timestamps or inconsistent locations, investigate using the guide to DAS troubleshooting. Correct the evidence path while the commissioning team can still reproduce the issue. Waiting for a real incident makes the same gap harder to resolve.
Who Owns the Retention Process?
Assign responsibility across the sensing, video, IT and security operations teams. One team may operate storage while another decides which incident records require preservation. The handover should explain both responsibilities and their communication path.
Review the plan after storage changes, platform migration or revised operating requirements. Retest a representative retrieval after changes that could affect indexing, timestamps or exports. Useful evidence retention is a maintained workflow connecting recorded events to understandable, retrievable records.