hx server detection aging indicator generated period

Prev Next

Sets the aging period for generated Endpoint Security (HX) indicators of compromise (IOCs). A single indicator is composed of one or more conditions.

Old alerts and indicators are of limited value to your organization and reduce the performance of your system and analysts. By default, the Endpoint Security (HX) software automatically ages (removes) alerts and indicators after specified periods of time. This command allows you to specify the aging period after which older alerts and indicators are removed.

Syntax

[no] hx server detection aging indicator generated period <number>

Parameters

no

Resets the indicator aging period to the default setting.

period <number>

Specify the number of seconds for the aging period for HX indicators. Valid values range from 60 seconds through 31536000 seconds (one year). The default is 1209600 seconds (14 days).

Example

The following example sets the indicator aging period to one day (86400 seconds):

hostname (config) # hx server detection aging indicator generated period 86400

User role

Admin

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Endpoint Security (HX): Release 2.5