Process Guard receives events from the endpoints for each unique process attempt to access LSASS. These events are stored in the Endpoint Security database for a finite period, after which they are discarded. Use the Data Aging Settings to specify how long to retain events. The default value is 30 days.
Data Aging
- Published on Sep 11, 2026
- 1 minute(s) read
Was this article helpful?
Related articles
- Endpoint Security Modules (HX) > Process Tracker Module > Endpoint Security Process Tracker Module User Guide Release 1.3.166 > Configuring the Process Tracker module > Configuring the Process Tracker server module
- Endpoint Security Modules (HX) > Process Guard > Endpoint Security Process Guard Module User Guide Release 1.7.0 > Configuring the Process Guard Module > Configuring the Process Guard Agent Policy
- Endpoint Security Modules (HX) > Process Guard > Endpoint Security Process Guard Module User Guide Release 1.7.0 > Installing the Process Guard Module