You can control how long triage, data, and file acquisition requests and results are retained. You can configure these settings using CLI commands; this functionality is not available through the Endpoint Security (HX) Web UI. The Endpoint Security (HX) appliance automatically deletes acquisitions if an Administrator, Analyst, or Investigator uses the Web UI to manually delete the associated agent.
Caution
Do not change the acquisition aging settings without consulting Trellix Customer Support.
You can control the following acquisition aging functions using acquisition aging settings:
Setting | Description |
|---|---|
Enable or disable aging settings | You can enable all acquisition aging settings. See Enabling or disable all acquisition aging settings using the CLI . |
Set the aging period for completed acquisitions | You can specify the aging period after which completed acquisitions are deleted. See Specifying the completed acquisition aging period using the CLI . |
Set the aging period for pending acquisitions | You can specify the aging period after which pending acquisitions are deleted. A pending acquisition request is one that is waiting to be processed. See Specifying the pending acquisition aging period using the CLI . |
Set the aging period for failed acquisitions | You can specify the aging period after which failed acquisition requests are deleted. See Specifying the failed acquisition aging period using the CLI . |
In addition, you can control acquisition aging by changing the amount of disk space allotted for acquisitions. When the total disk size of completed acquisitions exceeds a specified limit, the Endpoint Security (HX) appliance deletes the oldest completed acquisitions until enough disk space is cleared to bring the total under the specified limit. Acquisitions that are not yet completed are unaffected. See Setting disk utilization limits for acquisitions .
Admin access