Use the Aging Settings page to control how long the Endpoint Security (HX) stores indicator rules, alerts, and host endpoints.
For complete information, see Indicator and alert aging and Specifying host aging intervals .
.png)
The Aging Settings page has two parts: an indicator and alert aging section and a host aging section.
To access the Aging Settings page, select Aging Settings from the Configure section of the mainmenu.
Admin access
Indicator & Alert Aging settings
The Indicator & Alert aging settings allow you to specify how often indicator rules and alerts that originate from Trellix appliances are deleted from the system. (Custom indicator rules are not affected by these settings.)
Field | Affects | Description |
|---|---|---|
Delete indicator rule when it's had no alerts for... | Indicator rules | Sets the number of days after which an indicator that has triggered no alerts is automatically deleted. Valid values range from 1 day to 365 days. If you select this setting, you cannot select the No auto-deletion setting. |
No auto-deletion; I will delete indicator rules manually | Indicator rules | Indicates that indicator rules should never be automatically deleted. If you select this setting, you cannot select the Delete indicator when... setting. |
Delete alerts after | Alerts | Sets the number of days after which alerts are deleted. Valid values range from 1 day to 365 days. |
Click Reset to defaults for any of these settings to return to the default values.
Host Aging settings
The Host Aging settings allow you to specify how often hosts are deleted from the system and when inactive hosts are included in Dashboard tally.
Field | Description |
|---|---|
Delete hosts from the database after ... | Sets the number of days after which a host is automatically deleted. Valid values range from 1 day to 365 days. If you select this setting, you cannot select the No auto-deletion setting. |
No auto-deletion; I will delete hosts manually | Indicates that hosts should never be automatically deleted. If you select this setting, you cannot select the Delete hosts from the database... setting. |
Show on the dashboard when hosts are inactive for | Sets the number of days for which a host must be inactive before it is included in the Dashboard inactive hosts tally. Valid values range from 1 day to 365 days. |
Click Reset to defaults for any of these settings to return to the default values.