Retention
The Retention tab lets you configure how much historical data Guardian stores for each data category.

The Retention tab displays a set of data category cards in a two-column layout. Each card shows one or more sliders you can adjust to control how much data Guardian stores. Some categories also have a COLLECTING / DISABLED toggle, and some offer Advanced options that let you set per-subcategory limits within the overall total.
Expiration
Sets the maximum age of stored items in days. When an item exceeds this age, the system deletes it. Set to Never to keep items indefinitely.
Retention level
Sets the maximum number of items to store. When the limit is reached, the system deletes the oldest items to make room for new ones.
Space retention level
Sets the maximum disk space to use for storing items. When the limit is reached, the system deletes the oldest items.
Discard rate
Sets the maximum rate of incoming items per minute. The system discards new items when they exceed this threshold.
Data categories
The following data categories appear on the Retention tab. Categories that require optional features only appear when you have licensed and enabled those features on this sensor.
| Data category | Controls | Notes |
|---|---|---|
| Left column (top to bottom) | ||
| Alerts | Retention level | Deleting an alert also deletes the related trace file. Advanced options let you set a separate sub-limit for alerts outside the active security profile. |
| Captured logs | Retention level | |
| CLI action requests | Retention level | |
| Extended network statistics | Space retention level | Can be toggled on or off. |
| Link events | Retention level, Discard rate | Can be toggled on or off. Enable only in small environments. |
| Node CPE changes | Retention level | |
| Node points | Retention level | |
| Reports saved locally | Retention level, Expiration | |
| Arc support archives | Retention level, Expiration | |
| Smart Polling execution history | Retention level | |
| Traces: generated | Retention level, Space retention level | Advanced options let you set sub-limits for traces generated by high risk alerts, medium risk alerts, low risk alerts, and by user request. The space retention level control is not available on systems where traces use tmpfs-based storage. |
| User sessions | Retention level | Applies to UI user sessions only. Users must reconnect when their session is purged. |
| Right column (top to bottom) | ||
| Audit | Retention level, Expiration | |
| Captured URLs | Retention level, Discard rate | Can be toggled on or off. Enable only in small environments. |
| Dashboard configurations | Retention level | |
| Health logs | Retention level | |
| Node CPEs | Retention level | |
| Node CVEs | Retention level | Requires Vulnerability Assessment. |
| Files quarantine | Retention level | Applies to monitored files reconstructed for analysis. |
| Scheduled updates | Retention level | |
| Time machine snapshots | Space retention level, Retention level | |
| Traces: generated continuous | Space retention level, Retention level | |
| Traces: uploaded | Retention level | |
| Variables history | Retention level | |