Indicator rules can be removed in a variety of ways:
You can manually delete custom indicator rules.
Indicator rules can be automatically deleted (or aged). See Indicator rule aging .
Note
When an indicator rule is deleted, all associated alerts are automatically deleted.
This topic describes how to manually delete custom indicator rules using the Endpoint Security (HX) Web UI. You cannot use the CLI to delete indicator rules.
Administrator, Senior Analyst, or Investigator access.
Select Rules from the Configure section of the main menu. The Rules page appears.
On the Indicators tab, in the Indicators grid, select the checkbox to the left of the indicator rule that you want to delete.
In the Actions list, click Delete indicator, and then click Go.
The custom indicator rule is deleted.