The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Data retention

Prev Next

Trellix NDR continuously purges old alerts and Layer 7 metadata to ensure that the appliance maintains sufficient disk space. Data aging occurs automatically when storage thresholds are reached.

How data retention operates

Data retention is governed by a strict First In, First Out (FIFO) lifecycle. When the database reaches a predefined capacity threshold, the system automatically purges the oldest records to allocate room for incoming network telemetry.

Data retention and health check field definitions

The appliance health check provides real-time visibility into the storage state and database health boundaries.

Storage and maintenance parameters

The following table defines the metrics and fields used to manage data aging:

Field Name

Description

Type

Number of days for which to keep the metadata index Open

Configures the maximum number of days to keep the Layer 7 metadata open before it undergoes automatic purging.

The default value is 180.

Integer (Days)

Number of days for which to keep the alert index Open

Configures the maximum number of days to keep the alert records open before it undergoes automatic purging.

The default value is 180.

Integer (Days)

Alert Retention Date

Displays the oldest chronological date for which security alert or threat incident logs actively exist on the appliance database.

Date / Timestamp

Nspect Retention Date

Displays the oldest chronological date for which Nspect layer 7 metadata actively exists on the appliance database.

Date / Timestamp

Note

If an appliance is newly deployed or has not yet reached its maximum storage volume threshold, the Alert Retention Date and Nspect Retention Date fields display blank dashes (--). This indicates that no historical data has aged out or been deleted.