Trellix NDR continuously purges old alerts and Layer 7 metadata to ensure that the appliance maintains sufficient disk space. Data aging occurs automatically when storage thresholds are reached.
How data retention operates
Data retention is governed by a strict First In, First Out (FIFO) lifecycle. When the database reaches a predefined capacity threshold, the system automatically purges the oldest records to allocate room for incoming network telemetry.
Data retention and health check field definitions
The appliance health check provides real-time visibility into the storage state and database health boundaries.
Storage and maintenance parameters
The following table defines the metrics and fields used to manage data aging:
Field Name | Description | Type |
|---|---|---|
Number of days for which to keep the metadata index Open | Configures the maximum number of days to keep the Layer 7 metadata open before it undergoes automatic purging. The default value is 180. | Integer (Days) |
Number of days for which to keep the alert index Open | Configures the maximum number of days to keep the alert records open before it undergoes automatic purging. The default value is 180. | Integer (Days) |
Alert Retention Date | Displays the oldest chronological date for which security alert or threat incident logs actively exist on the appliance database. | Date / Timestamp |
Nspect Retention Date | Displays the oldest chronological date for which Nspect layer 7 metadata actively exists on the appliance database. | Date / Timestamp |
Note
If an appliance is newly deployed or has not yet reached its maximum storage volume threshold, the Alert Retention Date and Nspect Retention Date fields display blank dashes (--). This indicates that no historical data has aged out or been deleted.