hx server detection aging condition generated period

Prev Next

Sets the aging period for Endpoint Security (HX) conditions that were generated by indicators from other Trellix products (such as Network Security and Email Security — Server appliances) or imported via a script.

Old conditions are of limited value to your organization and reduce the performance of your system and analysts. By default, the Endpoint Security (HX) software automatically dissociates conditions from integration-generated indicators based on their age. This command allows you to specify the aging period after which this dissociation occurs.

Note

Conditions are not removed from the database. They are only dissociated from their associated integration-generated indicators.

Custom conditions are not affected by condition aging settings.

Syntax

[no] hx server detection aging condition generated period <number>

Parameters

no

Resets the condition aging period to the default setting.

period <number>

Specify the number of seconds for the aging period for conditions that were generated by indicators from other Trellix products or imported via a script. Valid values range from 60 seconds through 31536000 seconds (one year). The default is 2592000 seconds (30 days).

Example

The following example sets the condition aging period to one day (86400 seconds):

hostname (config) # hx server detection aging condition generated period 86400

User role

Admin

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Endpoint Security (HX): Release 3.2