Limits and defaults
Find any Foxborne limit or default in one place, from file sizes, the ordering bound and collector budgets to sessions, retention, exports, rule thresholds and zoom, with where each is set and whether you can change it.
On this page15
Values marked "example" are the settings of the example deployment. The others are fixed by Foxborne or are its defaults. Every change made in Settings is recorded in the audit log.
Import#
| Item | Default | Other choices | Set in |
|---|---|---|---|
| Largest file | 250 MB per file | 1 GB, 4 GB | Settings, Import, Largest file |
| Decompression limit | 2 GB per bundle | Fixed | Settings, Import |
| Formats on Import files | PX4 ULog, journalctl JSON, collector JSONL, receiver JSONL | Fixed | Settings, Import |
| Format detection | The first 4,096 bytes of each file | Fixed | Import files |
Oversized files are refused with a reason, never truncated: Larger than the 250 MB limit. Ask an admin to raise it for this import. Parsing streams the file, so memory does not grow with its size.
The size limit and format detection above apply to the four formats that Import files accepts. Foxborne also reads IRIG 106 Chapter 10 recordings (.ch10) and range records (.csv, .json); Supported file formats covers all six.
Time and position#
| Item | Default | Other choices | Set in |
|---|---|---|---|
| Ordering bound | 2.0 s | 0.5 s, 1.0 s, 5.0 s | Settings, Time and position, Ordering bound |
| Times | UTC, with Z on clock readouts | Fixed | Settings, Time and position |
| Positions | MGRS at 10 m, on screen and in reports | Fixed | Settings, Time and position |
| Latitude and longitude | 5 decimal places, beside MGRS in the evidence inspector | Fixed | Evidence inspector |
Above the ordering bound, Foxborne makes no before or after claim between two sources, whatever the times say. Lowering it makes more pairs unknown, and raising it is recorded in every report produced afterwards.
Collector#
| Item | Default | Other choices | Set in |
|---|---|---|---|
| Sample rate | 1 per second | 2 per second, 5 per second | Sources, Vehicle collectors, Collector policy, Edit policy |
| Spool budget | 100 MB | 250 MB, 500 MB | Edit policy |
| Journal units | perception.service, mavlink-router.service, chronyd.service, collector.service, kernel (example) | Any list | Edit policy |
| Processes to sample | perception_node, mavlink-routerd (example) | Any list | Edit policy |
| Redact from journal lines | AKIA[0-9A-Z]{16}, Bearer [A-Za-z0-9._-]+ (example) | Any patterns | Edit policy |
| Never collected | Environment variables, process arguments, camera frames | Fixed | Stated under What the collector reads in Collector policy |
| Enrollment token | Works once and expires 30 minutes after the drawer shows it | Fixed | The vehicle's Enroll drawer |
| Collector version | 0.8.1 | Update on a row running an older version | Vehicle collectors |
A policy change applies to every enrolled vehicle at its next check-in. When the spool budget fills, the collector drops low-priority samples first and writes a lost-data marker. Update schedules collector 0.8.1, which the vehicle downloads from your deployment the next time it is on the ground and online.
Sources#
| Item | Default | Other choices | Set in |
|---|---|---|---|
| Access | Read-only, verified by the connection test | Fixed | Add a source |
| Schedule | Watch for new files, on a source you add | Any schedule text, with Edit | The source's drawer |
| Pause | Off | Pause, Resume | The source's drawer |
Edits to a source apply from its next sync. A paused source reads no new files, and files already imported stay as they are.
Egress#
| Item | Default | Other choices | Set in |
|---|---|---|---|
| Egress to a destination | Off | An admin turns on each destination | Integrations |
| Foxborne, Inc. and map and tile services | Nothing is sent | Fixed | Stated on Hosting, Outbound connections |
Outbound connections on Hosting lists every destination whose egress is on, after its four fixed rows. See Egress, data classes and the delivery ledger.
Access and sessions#
| Item | Default | Other choices | Set in |
|---|---|---|---|
| Idle timeout | 30 minutes (example) | 15 minutes, 1 hour | Access, Sign-in, Sessions, Edit |
| Longest session | 12 hours (example) | 8 hours, 24 hours | Sessions, Edit |
| Allowed networks | 10.0.0.0/8 and the VPN range (example) | Any address ranges | Sessions, Edit |
| Two-factor | Required for everyone | Fixed | Access, Sign-in |
| Role for an invitation | Investigator | Admin, Reviewer, Viewer, Auditor | Invite |
| Role change | Takes effect on the person's next request | Fixed | Access, Members |
| Removal in the console | They lose access at once | Fixed | Access, Members |
| Removal through SCIM | Within five minutes of removal in the identity provider | Fixed | Your identity provider |
| Identity provider change | Signs everyone out | Fixed | Single sign-on, Edit |
Retention#
| Item | Default | Other choices | Set in |
|---|---|---|---|
| Original files | 2 years after import (example) | 30 days, 1 year, 7 years after import | Settings, Retention |
| Events and notes | Same as originals | Fixed | Settings, Retention |
| Reports and case files | 10 years (example) | 1 year, 5 years | Settings, Retention |
| Legal holds | Held runs are never deleted, whatever the policy | Fixed | Settings, Retention |
| Audit log | Never deleted | Fixed | Stated on Hosting |
Originals are deleted with a certificate that lists each hash. Shortening retention does not delete anything on hold.
Exports#
| Item | Default | Other choices | Set in |
|---|---|---|---|
| Export format | PDF case file with CUI markings (L1) | MCAP, Parquet, CSV and JSONL, originals with a SHA-256 manifest, BagIt bundle, MATLAB .mat v7.3 (L2) | Export dialog on the incident |
| Export destination | Exports bucket | Download, On-premises share, Removable media | Export dialog on the incident |
| Remove coordinates | On while the redaction policy is on | Off | Export dialog on the incident |
| Portion marks | Off | On | Export dialog on the incident |
| Coordinates on export | Removed (example) | Kept | Settings, Redaction, Remove coordinates on export |
| Audit log export format | JSON Lines | CSV | Audit log, Export |
| Audit log export range | Last 7 days | Last 30 days, Everything | Audit log, Export |
The audit export includes each entry's hash and the hash before it, so it can be verified offline. Case files carry your marking at the top and bottom of every page, with the designation indicator on the first.
Rule thresholds#
Thresholds are the example dataset's, and admins change them under Rules with Edit. A saved change creates the next minor version of the rule; findings already produced keep theirs.
| Rule | Threshold | Scope | Default state |
|---|---|---|---|
process_exit | 6 units on the allowlist | All vehicles | On |
service_restart | Any restart | All vehicles | On |
memory_pressure | RSS at or above 6,144 MiB for 3 samples | Q4 vehicles. Override for T4 vehicles: 24,576 MiB | On |
telemetry_gap | More than 3 s without a HEARTBEAT | All vehicles | On |
device_disconnect | Any disconnect on an allowlisted port | T4 vehicles | On |
vibration_high | Above 24 m/s² for 1 s (T4), 12 m/s² (Q4) | All vehicles | On |
failsafe_entered | Any failsafe | All vehicles | On |
topic_stall | No sample for 5 times the median period | All vehicles | On |
gnss_jamming | jamming_state 3 for 1 s | All vehicles | On |
gps_quality_drop | eph above 2.5 m or fewer than 8 satellites for 2 s | All vehicles | On |
log_dropout | Dropout of 50 ms or longer | All vehicles | On |
clock_uncertain | Anchor missing or error above 2 s | All sources | Always on, locked |
battery_sag | More than 2.0 V in 2 s above 70% track current | T4 vehicles | Off |
A switch change applies to the next import and does not change the version. clock_uncertain cannot be switched off or edited.
Updates#
| Item | Value | Set in |
|---|---|---|
| Delivery | A signed .fxb bundle that your administrator brings in; nothing is downloaded | Hosting, Install an update |
| Checks before install | Read the bundle, check the signature, check the bill of materials, check the database migration | Install an update |
| Downtime | None. Workers restart one at a time. | Install an update |
The install button stays disabled until every check has finished.
Timeline and evidence views#
These values are fixed.
| Item | Value |
|---|---|
| Narrowest timeline window | 40 ms |
| Narrowest window from the whole-run strip | 50 ms |
| [ and ], Zoom out and Zoom in | Double or halve the window |
| Wheel zoom with Ctrl, ⌘ or Alt | Each step scales the window by 0.8 or 1.25, around the pointer |
| Order against nearby events | Up to 7 events within 6 s of the selected one |
| Breadcrumbs | Every source in the 3 minutes before the event, 12 to a page with this event first |
| Across the fleet | The last 30 days |
| Unit history | systemd events and kernel kill lines within 12 s of the event |
| Memory around this event, Vibration around this event | From 8 s before to 4 s after the event |
Lists and pages#
Every table and list in the console pages itself. Under each one, the controls give the range on screen, such as 1 to 10 of 20, and the pages. Once a list holds more than its first page, or more than 10 rows, Rows sets how many show at once: 10, 25, 50 or the list's own size. The page you are on is kept while a list updates in place, starts again at page 1 when a filter changes what it holds, and moves to the page of an event you select.
| List | Rows per page |
|---|---|
| Most tables and lists | 10 |
| Events in view, Audit log, Delivery ledger | 25 |
| Activity on an incident | 15 |
| Breadcrumbs on an event page | 12 |
| Tags on an event page | 24 |
| Fleet on Range status, each group | 12 |
| Sorties, Open incidents, Rule firings and Approvals on Range status | 6 |
| Findings on the Reconstruction tab, report History, Seen before | 8 |
| The update list under Updates on Hosting | 5 |
| Vehicles on the Fleet tab of Reports | 16 |
| A saved report's Generated list, in its drawer | 6 |
Map#
These values are fixed.
| Item | Value |
|---|---|
| Zoom range | 0.06 to 12 pixels per meter |
| Zoom in and Zoom out | 1.6 times per click, about the center |
| Wheel zoom with Ctrl, ⌘ or Alt | 1.25 times per step, about the pointer |
| Fit on an incident | The track in the incident window, at least 460 m across for a UGV and 720 m for a UAS |
| First view of a run | The whole run, at least 500 m across |
| MGRS grid spacing | 50 m to 2,000 m, at least 90 pixels between lines |
| Position readout | MGRS at 10 m |
Search#
These values are fixed.
| Item | Value |
|---|---|
| Shortest query | 2 characters |
| Results per group | Up to 5 incidents, 5 runs, 6 evidence items and 4 vehicles |
| Evidence | Event IDs match by prefix at any length; titles match on queries longer than 3 characters |
Related#
- Thresholds, scopes and overrides explains how to change a rule.
- Set the collector policy covers every collector policy field.
- Retention, holds and redaction explains the retention settings.
- Install an update walks through an update.