To set the condition aging interval using the CLI:
Enable the CLI configuration mode:
hostname > enable
hostname # configure terminal
Set the condition aging interval:
hostname (config) # hx server detection aging condition generated period <seconds>
where <seconds> is the number of seconds for the aging period for conditions. The default is 2592000 seconds (30 days). Valid values range from 60 seconds to 31536000 seconds (one year).
Endpoint Detection and Response with Forensics (EDRF) > Detect and handle potential threats with EDRF > Configure EDRF to detect potential threats > Threat detection using IOC rules > Threat detection using IOC rules in the Forensics workspace > Indicator rule aging > Specify indicator rule aging settings