Defaults
| Data | Default |
|---|---|
| Events | 90 days |
| Unparsed events | 14 days |
| Analyst audit trail | 365 days |
| Playbook run traces | 90 days |
| Notifications | 90 days |
| Baseline data | 14 to 45 days depending on the baseline |
| Alerts, cases, reports, tickets | Kept until deleted |
XenXDR enforces retention automatically and reclaims the space in the background.
Changing it
Retention is a deployment setting. Change the values in the environment file and apply them with the retention script included in the deployment files; the release notes for your version give the exact command.
Disk
Plan disk for the events retention: see the sizing table under Requirements. The Settings › System page shows database size and growth so you can see a full disk coming.
Data subject requests
Support provides the procedure for erasing a specific person's data from telemetry, for hosted tenants and self-hosted deployments alike.