The Threat Analyzer facility operates in the following manner: Manager receives alerts from the Sensors and organizes the alerts by the timestamps with alert; the most recent alerts are listed first. All alerts are stored in the database, while a preset number of the most recent alerts are also maintained in a cache, known as the alert cache. The alert cache contains only unacknowledged alerts, and is exclusive to a Real-Time Threat Analyzer query; a Historical Threat Analyzer query only pulls alerts from the database. The difference in Threat Analyzer operations is detailed in the subsections that follow. .