Data retention

After purchasing your license retention add-ons, you can view details about your Cortex XSIAM licenses and retention add-ons by selecting **Settings** → **Cortex XSIAM License**. For more information on your storage license details, see [Dataset Management](../../configure-cortex-xsiam/data-management/dataset-management).

### **Default retention periods**

The following table summarizes the default retention periods for Cortex XSIAM:

| Data Type | Default Retention Period |
| ------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Ingested data | 31 days |
| Cases and Issues data | <p>186 days</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Case data is retained according to the <strong>Last Updated</strong> date.</p><p>Issue data is retained according to the <strong>Observation Time</strong>. Data collected within these dates is kept and displayed for 186 days. To ensure the accuracy of issues, Cortex XSIAM provides a grace period of up to 31 days for issues displayed in the Issues View, Issues table, and Cases View.</p></div> |
| Agentic AI chats and artifacts | 186 days |
| Forensic data | <p>365 days</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Requires the Forensics add-on.</p></div> |
| Audit logs | 365 days |
| Query data | 186 days |

### **Retention add-ons**

Retention add-ons are provided for ingested data and Cases and Issues data. Minimum requirements are dependent on the license type. You can purchase one or more of the following add-ons:

| Feature | Description |
| --------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Additional Cases and Issues Retention | <p>An additional 31-day hot storage of Case and Issue data apart from the default 186 days.</p><p>Available for purchase per month for each endpoint. This retention add-on also extends agentic AI chats and artifacts retention by 31 days.</p> |
| Period-Based Retention - Hot Storage (All datasets) | <p>Fully searchable storage for investigation and threat hunting of ingested data, and Cases and Issues data.</p><p>Requires purchasing a minimum of one month of the additional retention.</p> |
| Additional Hot Storage (Selected datasets) | <p>Flexible hot storage-based retention to help accommodate varying storage requirements for different retention periods and datasets. Fully searchable storage for investigation and threat hunting of ingested data.</p><p>Available for purchase with storage for a minimum of 1,000 GB.</p> |
| Period-Based Retention - Cold Storage | <p>Lower-cost storage of ingested data for long-term compliance needs with limited search options.</p><p>Requires purchasing a minimum of six months of additional retention.</p> |