Retention

How long each kind of data is kept, and how to change it.

Defaults

DataDefault
Events90 days
Unparsed events14 days
Analyst audit trail365 days
Playbook run traces90 days
Notifications90 days
Baseline data14 to 45 days depending on the baseline
Alerts, cases, reports, ticketsKept until deleted

XenXDR enforces retention automatically and reclaims the space in the background.

Changing it

Retention is a deployment setting. Change the values in the environment file and apply them with the retention script included in the deployment files; the release notes for your version give the exact command.

Disk

Plan disk for the events retention: see the sizing table under Requirements. The Settings › System page shows database size and growth so you can see a full disk coming.

Data subject requests

Support provides the procedure for erasing a specific person's data from telemetry, for hosted tenants and self-hosted deployments alike.