Specifying alert aging settings

Prev Next

The following table summarizes the alert aging settings available.

Setting

Description

Alert Aging Interval

The aging interval of triggered alerts on the system. The setting can be set using the Endpoint Security (HX) Web UI or the CLI. An alert is automatically removed from the system when the time since its last occurrence is greater than this interval.

Web UI range: 1 day through 365 days

CLI range: 60 through 31536000 seconds (1 min through 365 days)

Default: 2592000 seconds (30 days)

See Setting the alert aging interval.

False Positive Alert Aging Interval

The aging interval of alerts marked as false positive alerts on the system. The setting can only be changed using the CLI.

CLI range: 60 through 31536000 seconds (1 min through 365 days)

Default: 86400 seconds (one day)

See Setting the false positive alert aging interval using the CLI.

Source Alert Aging Enabled

Enables or disables the source alert aging interval. When the aging interval is reached, source alerts are removed from the database. If aging is disabled, source alerts are not automatically removed. The source alert aging interval can be enabled or disabled using the CLI.

Default: Enabled

See Enabling source alert aging using the CLI and Disabling source alert aging using the CLI.

Source Alert Aging Interval

The aging interval of source alerts on the system. A source alert is automatically removed from the system when the time since its last occurrence is greater than this interval.

CLI range: 60 through 31536000 seconds (1 min through 365 days)

Default: 2592000 seconds (30 days)

See Setting the source alert aging interval using the CLI.