When an indicator rule is deleted, all associated alerts are automatically deleted.
This topic describes how to manually delete custom indicator rules using the Endpoint Security (HX) Web UI. You cannot use the CLI to delete indicator rules.
Prerequisites
Administrator, Senior Analyst, or Investigator access.
To manually delete custom indicator rules using the Web UI:
Select Rules from the Configure section of the main menu. The Rules pageRules page appears.
On the Indicators tab, in the Indicators grid, select the checkbox to the left of the indicator rule that you want to delete.
In the Actions list, click Delete indicator, and then click Go.
Endpoint Detection and Response with Forensics (EDRF) > Detect and handle potential threats with EDRF > Configure EDRF to detect potential threats > Threat detection using IOC rules > Threat detection using IOC rules in the Forensics workspace > Indicator rule aging
Endpoint Detection and Response with Forensics (EDRF) > Detect and handle potential threats with EDRF > Configure EDRF to detect potential threats > Threat detection using IOC rules > Threat detection using IOC rules in the Forensics workspace
Endpoint Detection and Response with Forensics (EDRF) > Detect and handle potential threats with EDRF > Configure EDRF to detect potential threats > Threat detection using IOC rules > Threat detection using IOC rules in the Forensics workspace > Maintain custom indicator rules