Retention time for new datasets

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Retention time for new datasets

L2 Linker

Hi all

 

Does someone know which retention period is used for datasets created through correlation rule or scheduled query?

 

1 accepted solution

Accepted Solutions

Hi Micomi, 

 

The Correlation Rule data set falls under a custom dataset where the base license includes 30 days of hot retention for both endpoint data and Pro per GB data.

 

You may view a summary of current retention entitlements by navigating to Settings > Configurations > Dataset Management page.

jtalton_0-1701185339616.png

 

Also, a new storage-based add-on license can be purchased per dataset with a Pro GB license in 30-day increments. You may reach out to your SE for additional questions. 

Reference "Flexible hot storage retention license" in the October 2023 Release notes

October 2023 • Cortex XDR Release Notes • Reader • Palo Alto Networks documentation portal

 

Thank you!

If you found this answer helpful, please select Accept as Solution.

View solution in original post

3 REPLIES 3

L3 Networker

Hi Micomi, 

 

For XQL Search capabilities, Cortex XDR enforces retention on all log-type datasets excluding Host Inventory, Vulnerability Assessment, Metrics, and Users. This includes Correlation rules. 

 

Cortex XDR Pro per Endpoint and Cortex XDR Cloud per Host

  • 30-day Ingested Data
  • 180-day Alert and Incident Data
  • 365-day Forensic Data

Cortex XDR Pro per GB

  • 30-day Ingested Data
  • 180-day Alert and Incident Data

Incident and alert data are retained according to the last Update and Creation dates, respectively. Reference License Retention • Cortex XDR Pro Administrator Guide • Reader • Palo Alto Networks documentation p...

 

If you found this answer helpful please select Accept as Solution.

 

Thank you

If you found this answer helpful, please select Accept as Solution.

Hi @jtalton 

 

Thanks for you answer. I read this documentation before. When I create a new dataset through correlation rule I get a dataset type "correlation". If creating a new dataset via XQL Query I get the type "user". By just reading the documentation I'm not sure if these types have any retention period set and if a retention period is set I don't know if it's 30 or 180 days.

Hi Micomi, 

 

The Correlation Rule data set falls under a custom dataset where the base license includes 30 days of hot retention for both endpoint data and Pro per GB data.

 

You may view a summary of current retention entitlements by navigating to Settings > Configurations > Dataset Management page.

jtalton_0-1701185339616.png

 

Also, a new storage-based add-on license can be purchased per dataset with a Pro GB license in 30-day increments. You may reach out to your SE for additional questions. 

Reference "Flexible hot storage retention license" in the October 2023 Release notes

October 2023 • Cortex XDR Release Notes • Reader • Palo Alto Networks documentation portal

 

Thank you!

If you found this answer helpful, please select Accept as Solution.
  • 1 accepted solution
  • 1331 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!