Sets the aging period for generated Endpoint Security (HX) indicators of compromise (IOCs). A single indicator is composed of one or more conditions.
Old alerts and indicators are of limited value to your organization and reduce the performance of your system and analysts. By default, the Endpoint Security (HX) software automatically ages (removes) alerts and indicators after specified periods of time. This command allows you to specify the aging period after which older alerts and indicators are removed.
Syntax
[no] hx server detection aging indicator generated period <number>
Parameters
no
Resets the indicator aging period to the default setting.
period <number>
Specify the number of seconds for the aging period for HX indicators. Valid values range from 60 seconds through 31536000 seconds (one year). The default is 1209600 seconds (14 days).
Example
The following example sets the indicator aging period to one day (86400 seconds):
hostname (config) # hx server detection aging indicator generated period 86400
User role
Admin
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Endpoint Security (HX): Release 2.5