Cortex XDR Deletion

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cortex XDR Deletion

L0 Member

Hi,

 

We have endpoints that we are considering deleting from our Gateway. It is my understanding that this is mainly a cosmetic/license recovery action, but my question is regarding the data from that endpoint. I found this in the documentation

 

  • Data associated with the deleted endpoint is displayed in the Action Center tables and in the Causality View for the standard 90 days retention period.

I was wondering if after the 90 day retention period, all data from the endpoint is deleted? In the event that we need to run historical XQL queries, will data from that endpoint remain searchable, or is everything purged after the 90 day period?

 

Thank you

1 REPLY 1

L5 Sessionator

Hi @ldonahue, thanks for reaching us using the Live Community.

 

Any other endpoint data follows the standard data retention from this document: https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/License-Ret...

 

  • 31-day Ingested Data

  • 186-day Alert and Incident Data

 

If this post answers your question, please mark it as the solution.

JM
  • 162 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!