Kaspersky Next XDR Expert

Configuring the retention period of alerts and incidents

Kaspersky Next XDR Expert allows you to reduce or increase the retention periods of alerts and incidents, depending on your needs. By default, the retention period of alerts and incidents is 360 days.

The child tenant copies the retention period of alerts and incidents from the parent tenant. If necessary, you can edit the retention period for the child tenant.

To configure the alert or incident retention period:

  1. In the main menu, go to Settings → Tenants.
  2. Click the name of the required tenant.

    The tenant's properties window opens.

  3. On the Settings tab, click Retention period.
  4. Specify the new retention period in one or both of the following fields:
    • Alert retention period (days)
    • Incident retention period (days)

    The minimum value is 1.

  5. Click Save.

The new retention period is configured.

Regardless of the configured retention period, if the expired alert is linked to an unexpired incident, the alert will be deleted only after the retention period of the linked incident expires. If the expired incident has unexpired linked alerts, the incident will be deleted only after the retention period of the linked alerts expires.