The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure data retention settings using the CLI

Prev Next

Configure your storage limits through the CLI to control how long historical data stays on your appliance before being purged.

  1. Log in to the Trellix NDR console as npadmin using your administrator credentials.

    $ ssh npadmin@<appliance_ip_address>
  2. Enter privileged mode on the CLI:

    npadmin@hostname> enable
  3. Enter configuration mode:

    npadmin@hostname# configure system
  4. Run the following commands to access the Elasticsearch Maintenance Menu:

    npadmin@hostname(config)# cluster maintenance 
    npadmin@hostname(cluster-maintenance)# maintenance

    The Elasticsearch Maintenance Menu appears and displays the default value of 180 days.

  5. Enter the number of days to keep the metadata index Open and press Enter.

  6. Enter the number of days to keep the alert index Open  and press Enter.

  7. Select one of the following menu options to complete the configuration:

    • Save — Enter X and press Enter to apply the values and return to the main menu.

    • Cancel — Enter C and press Enter to exit and return to the main menu.