Specify indicator rule aging settings

Prev Next

The following table summarizes the indicator rule aging settings available.

Setting

Description

Indicator Aging Enabled

Enables or disables the indicator rule aging interval. When the aging interval is reached, indicator rules are removed from the database. If aging is disabled, indicator rules are not automatically removed. The indicator rule aging interval can be enabled or disabled using the Endpoint Security (HX) Web UI or the CLI.

Default: Enabled

See Enabling or disabling indicator rule aging.

Indicator Aging Interval

The aging interval of indicator rules (IOC rules) on the system. The Endpoint Security (HX) software ages (deletes) indicator rules that have no alerts for this interval of time.

If indicator rule and alert aging is disabled, indicator rule aging does not occur.

Web UI range: 1 day through 365 days

CLI range: 60 through 31536000 seconds (1 min through 365 days)

Default: 1209600 seconds (14 days)

See Setting the indicator rule aging interval.

Condition Aging Enabled

Enables or disables the condition aging interval for conditions generated by indicator rules from other Trellix projects (such as NX Series and EX Series appliances). The condition aging interval can be enabled or disabled using the CLI.

When the condition aging interval is reached, conditions are not removed from the database. They are only dissociated from their associated indicator rules.

If indicator rule and alert aging is disabled, condition aging does not occur.

Default: Enabled

See Enabling or disabling condition aging.

Condition Aging Interval

The aging interval of conditions on the system. When the condition aging interval is reached, conditions are not removed from the database. They are only dissociated from their associated indicator rules.

If indicator rule and alert aging is disabled, condition aging does not occur.

CLI range: 60 through 31536000 seconds (1 min through 365 days)

Default: 2592000 seconds (30 days)

See Setting the condition aging interval using the CLI.