Sets the aging period for Endpoint Security (HX) conditions that were generated by indicators from other Trellix products (such as Network Security and Email Security — Server appliances) or imported via a script.
Old conditions are of limited value to your organization and reduce the performance of your system and analysts. By default, the Endpoint Security (HX) software automatically dissociates conditions from integration-generated indicators based on their age. This command allows you to specify the aging period after which this dissociation occurs.
Note
Conditions are not removed from the database. They are only dissociated from their associated integration-generated indicators.
Custom conditions are not affected by condition aging settings.
Syntax
[no] hx server detection aging condition generated period <number>
Parameters
no
Resets the condition aging period to the default setting.
period <number>
Specify the number of seconds for the aging period for conditions that were generated by indicators from other Trellix products or imported via a script. Valid values range from 60 seconds through 31536000 seconds (one year). The default is 2592000 seconds (30 days).
Example
The following example sets the condition aging period to one day (86400 seconds):
hostname (config) # hx server detection aging condition generated period 86400
User role
Admin
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Endpoint Security (HX): Release 3.2