Configure your storage limits through the CLI to control how long historical data stays on your appliance before being purged.
Log in to the Trellix NDR console as npadmin using your administrator credentials.
$ ssh npadmin@<appliance_ip_address>
Enter privileged mode on the CLI:
npadmin@hostname> enable
Enter configuration mode:
npadmin@hostname# configure system
Run the following commands to access the Elasticsearch Maintenance Menu:
npadmin@hostname(config)# cluster maintenance npadmin@hostname(cluster-maintenance)# maintenance
The Elasticsearch Maintenance Menu appears and displays the default value of 180 days.
Enter the number of days to keep the
metadata index Openand press Enter.Enter the number of days to keep the
alert index Openand press Enter.Select one of the following menu options to complete the configuration:
Save — Enter
Xand press Enter to apply the values and return to the main menu.Cancel — Enter
Cand press Enter to exit and return to the main menu.