Deleting forensic data

Prev Next

Triage and data acquisitions collected for a host endpoint are automatically deleted when the host is deleted. (Host endpoints may be automatically deleted if the host aging settings are set that way. See Specifying host aging intervals . Otherwise, acquisitions are retained as long as their associated host endpoints remain active.

You can manually delete triage and acquisition data to free acquisition space.

To manually delete forensic data from the Acquisitions page:
  1. Select Acquisitions in the Endpoint Security (HX) Web UI.

  2. In the Acquisitions grid, select the checkbox associated with the row in the grid you want to delete.

    Details about the row appear in the Acquisition Detail pane. You can expand these details to review some of the acquisition data in the Acquisition Detail pane.

    Note

    A single row in the grid may have both Triage Summary and data acquisition views. When you delete a row in the Acquisitions grid, you will delete both views.

  3. Select Delete acquisition from the Actions menu to delete the row.