Sets the aging period for Endpoint Security (HX) source alerts. Source alerts are notices of suspicious activity sent to the Endpoint Security (HX) software from other Trellix products (such as Network Security and Email Security — Server appliances).
Old source alerts are of limited value to your organization and reduce the performance of your system and analysts. By default, the Endpoint Security (HX) software automatically ages (removes) alerts after specified periods of time. This command allows you to specify the aging period after which older alerts are removed.
Syntax
[no] hx server detection aging source-alert period <number>
Parameters
no
Resets the source alert aging period to the default setting.
period <number>
Specify the number of seconds for the aging period for Endpoint Security (HX) source alerts. Valid values range from 60 seconds through 31536000 seconds (one year). The default is 2592000 seconds (30 days).
Example
The following example sets the source alert aging period to one day (86400 seconds):
hostname (config) # hx server detection aging source-alert period 86400
User role
Admin
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Endpoint Security (HX): Release 3.2