To enable or disable indicator rule aging using the Web UI:
Log in to the Endpoint Security (HX) Web UI.
Select Aging Settings on the Configure menu. The Aging Settings page appears.
To enable or disable the indicator rule aging using the Web UI:
To enable the indicator rule, specify an aging interval in the Delete indicator when it's had no alerts for: box in the Indicator and Alert box on the Aging Settings page. Valid values range from 1 through 365 days. This sets and enables the aging interval.
To disable the indicator rule, select the No auto-deletion; I will delete indicator rules manually option in the Indicator and Alert box on the Aging Settings page
Click Save to save your changes.
Note
To restore default settings, click Reset to default, and then click Save. If you click Cancel, Endpoint Security (HX) will return settings to the most recently saved values.
Endpoint Detection and Response with Forensics (EDRF) > Detect and handle potential threats with EDRF > Configure EDRF to detect potential threats > Threat detection using IOC rules > Threat detection using IOC rules in the Forensics workspace > Indicator rule aging > Specify indicator rule aging settings