To maintain a cluster:
Log in to the NDR CLI.
Enter privileged mode:
hostname > enableEnter the admin password:
[sudo] password for <npadmin>: <password>Enter configuration mode:
hostname # configure systemEnter the cluster maintenance menu:
user@hostname(config)# cluster maintenanceThe Elasticsearch Maintenance menu appears.
(S) Shutdown Cluster
(M) Maintainance
(C) Cancel and Exit
Enter your choice:
(Optional) Press S to shutdown the cluster.
Press M to enter the maintenance mode.
The Elasticsearch Maintenance menu is displayed.
Menu: (N) No of days for which to keep the index Open (C) Cancel and Exit (X) Save and Exit
Press N and press Enter to set the time period in days, for which you need to retain the data on your NDR appliance. This period is called the retention period. After the retention period, the older data on your appliance is automatically deleted to accommodate new data.
Enter any value between 1 and 1000, and then press Enter.
You cannot set the retention period as more than 1000 days. If you enter a value beyond 1000, the following error message is displayed: "Not a valid input. Try again".
Click X to save and exit.