hx server detection aging source-alert period

Prev Next

Sets the aging period for Endpoint Security (HX) source alerts. Source alerts are notices of suspicious activity sent to the Endpoint Security (HX) software from other Trellix products (such as Network Security and Email Security — Server appliances).

Old source alerts are of limited value to your organization and reduce the performance of your system and analysts. By default, the Endpoint Security (HX) software automatically ages (removes) alerts after specified periods of time. This command allows you to specify the aging period after which older alerts are removed.

Syntax

[no] hx server detection aging source-alert period <number>

Parameters

no

Resets the source alert aging period to the default setting.

period <number>

Specify the number of seconds for the aging period for Endpoint Security (HX) source alerts. Valid values range from 60 seconds through 31536000 seconds (one year). The default is 2592000 seconds (30 days).

Example

The following example sets the source alert aging period to one day (86400 seconds):

hostname (config) # hx server detection aging source-alert period 86400

User role

Admin

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Endpoint Security (HX): Release 3.2