- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-27-2023 07:41 AM
Hi all
Does someone know which retention period is used for datasets created through correlation rule or scheduled query?
11-28-2023 07:30 AM
Hi Micomi,
The Correlation Rule data set falls under a custom dataset where the base license includes 30 days of hot retention for both endpoint data and Pro per GB data.
You may view a summary of current retention entitlements by navigating to Settings > Configurations > Dataset Management page.
Also, a new storage-based add-on license can be purchased per dataset with a Pro GB license in 30-day increments. You may reach out to your SE for additional questions.
Reference "Flexible hot storage retention license" in the October 2023 Release notes
October 2023 • Cortex XDR Release Notes • Reader • Palo Alto Networks documentation portal
Thank you!
11-27-2023 02:52 PM
Hi Micomi,
For XQL Search capabilities, Cortex XDR enforces retention on all log-type datasets excluding Host Inventory, Vulnerability Assessment, Metrics, and Users. This includes Correlation rules.
Cortex XDR Pro per Endpoint and Cortex XDR Cloud per Host
Cortex XDR Pro per GB
Incident and alert data are retained according to the last Update and Creation dates, respectively. Reference License Retention • Cortex XDR Pro Administrator Guide • Reader • Palo Alto Networks documentation p...
If you found this answer helpful please select Accept as Solution.
Thank you
11-27-2023 11:35 PM
Hi @jtalton
Thanks for you answer. I read this documentation before. When I create a new dataset through correlation rule I get a dataset type "correlation". If creating a new dataset via XQL Query I get the type "user". By just reading the documentation I'm not sure if these types have any retention period set and if a retention period is set I don't know if it's 30 or 180 days.
11-28-2023 07:30 AM
Hi Micomi,
The Correlation Rule data set falls under a custom dataset where the base license includes 30 days of hot retention for both endpoint data and Pro per GB data.
You may view a summary of current retention entitlements by navigating to Settings > Configurations > Dataset Management page.
Also, a new storage-based add-on license can be purchased per dataset with a Pro GB license in 30-day increments. You may reach out to your SE for additional questions.
Reference "Flexible hot storage retention license" in the October 2023 Release notes
October 2023 • Cortex XDR Release Notes • Reader • Palo Alto Networks documentation portal
Thank you!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!