Symantec EDR endpoint search retention policy
search cancel

Symantec EDR endpoint search retention policy

book

Article ID: 266764

calendar_today

Updated On:

Products

Endpoint Detection and Response

Issue/Introduction

Endpoint searches, including failed searches, remain visible on the EDR appliance console for a long time.

Environment

EDR appliances

Cause

Purge retention is as designed.

Resolution

The Symantec EDR search result retention policy is as follows:

  1. Symantec EDR retains no more than 100 searches at a time.
  2. Some searches with Error State (red X icon), such as searches on empty groups, are exempt from the 100 count limit.  
  3. No search, regardless of the state, remains for more than 180 days.