License Retention - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM Administrator Guide

Cortex XSIAM
Creation date
Last date published
Administrator Guide

Learn more about the default retention periods provided for all Cortex XSIAM licenses and retention add-ons available.

All of the Cortex XSIAM licenses provide you with the following default retention periods:

  • 31-day Ingested Data

  • 180-day Alert and Incident Data

  • 365-day Forensics Data (requires Forensics add-on)

Incident and alert data are retained according to the last Update Date and Creation Date, respectively. Data collected within these dates is kept and displayed for 180 days. To ensure the accuracy of incidents, Cortex XSIAM provides a grace period of up to 31 days for alerts displayed in the Incidents View, Alerts table, and Casualty View.

For XQL Search capabilities, Cortex XSIAM enforces retention on all log-type datasets excluding Host Inventory, Vulnerability Assessment, Metrics, and Users.

Depending on your requirements and license add-ons, you can purchase one or more of the following retention add-ons on top of your license to extend your storage. You can view your retention storage duration in the Dataset Management page.

The following table lists the additional retention available for purchase for both Cortex XSIAM Enterprise and Cortex XSIAM Enterprise Plus licenses:


Retention add-ons are provided for ingested data, and alert and incident data unless noted otherwise. Minimum requirements are dependent on the license type.

Data Storage Lifecycle