> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy/cortex-xsoar-8-retention-policy-faqs/readme.md).

# Retention Policy and Enforcement

Retention policy for Cortex XSOAR 8 SaaS.

Cortex XSOAR SaaS operates a retention policy for the following data:

* Incidents

  Incidents are retained for 6 months, by default, after the incident was created in Cortex XSOAR. For more information, see [Incidents](#incidents).

  If using an MSSP/Multi-tenant environment, each child tenant has 6 months of incident retention by default. For more information, see [MSSP and Multi-Tenant Environments](#mssp-and-multi-tenant-environments).
* Indicators (not yet enforced)

  Indicators will be limited according to your license. For more information, see [Indicators](#indicators).

### Cortex XSOAR 8 SaaS incident retention policy

Cortex XSOAR SaaS includes an incident storage limit and a nominal retention charge for extended incident storage, which enables us to ensure the seamless availability of data and provide you with a reliable and efficient platform.

The incident retention policy is now being enforced for customers. Incident retention license add-ons can be purchased to extend the retention period.

Users can permanently retain up to 1000 specific incidents depending on their needs. The incident retention policy does not delete retained incidents, even after the 6-month retention period and any extension license period. Retaining an incident can be done for compliance or incident management reasons to ensure that the most valuable incidents are kept on the tenant and not deleted by retention enforcement or accidental removal.

{% hint style="info" %}
The retention policy does not apply to users who migrated from Cortex XSOAR 6 or purchased Cortex XSOAR 8 before January 2024 until their license renewal. After which, the retention policy applies.
{% endhint %}

#### What is the default Cortex XSOAR 8 SaaS incident retention period?

The default retention period for Cortex XSOAR 8 SaaS incidents is 6 months.

#### How is Cortex XSOAR 8 SaaS incident retention calculated?

The incident retention period is calculated from when the incident was created in Cortex XSOAR.

#### Can I extend Cortex XSOAR 8 SaaS incident retention?

You can easily extend the retention period according to your needs by purchasing a retention extension add-on.

#### Where can I find my Cortex XSOAR retention entitlement?

The retention entitlement will be visible on the Cortex XSOAR license page **Settings & Info** → **Cortex XSOAR License**.

![xsoar-license.png](https://1878857290-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FB9wj8hV3yPF9Sj7EWql1%2Fuploads%2Fgit-blob-60eae0b47c62ed43487391ac532e976833e7d0db%2F61509892f06676c0059f5aece700854ee2d412ddf79c49f637f9300f7086cb88.png?alt=media)

### Cortex XSOAR 8 SaaS MSSP and multi-tenant incident retention

By default, each child tenant retains incidents for 6 months. The retention period is calculated from when the incident was created in Cortex XSOAR.

You can purchase incident retention licenses to extend the incident retention of one or more child tenants. These licenses, once purchased, are available in the Cortex Gateway for allocation to child tenants. For more information, see [Allocate incident retention licenses](/cortex-xsoar-8-saas/multi-tenant/onboard-cortex-xsoar-multi-tenant/step-3.-allocate-incident-retention-licenses.md).

{% hint style="info" %}
**Note**

Once an incident retention license has been assigned to a child tenant, the license cannot be removed from the child tenant or assigned to another child tenant via the Cortex Gateway. If you need to remove or reassign an incident retention license, contact Customer Support.

If you delete a child tenant, any incident retention licenses assigned to that tenant are returned to the main account and can be reallocated.
{% endhint %}

#### How do I assign incident retention licenses to a new child tenant?

You can assign retention licenses when creating a new child tenant.

![child-retention.png](https://1878857290-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FB9wj8hV3yPF9Sj7EWql1%2Fuploads%2Fgit-blob-defb823266764d5e8de837b62cb82dec3d7362d4%2Fca9a66a03425575f5b5cd7838e2877fad8594ab52bd265bf1a12c2d3b0d89e08.png?alt=media)

#### How do I assign incident retention licenses to an existing child tenant?

Users can manage child tenant retention licenses from Cortex Gateway.

![license-activation-mt.png](https://1878857290-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FB9wj8hV3yPF9Sj7EWql1%2Fuploads%2Fgit-blob-c9b94edc64abd42e8bd65a23fa03ccae2f8381f4%2F3ad5badba049e164c59b72adb4dae7822b53418ce6b3d6db12f4b8a110b89b6e.png?alt=media)

When clicking Manage Incident Retention Licenses:

![manage-retention.png](https://1878857290-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FB9wj8hV3yPF9Sj7EWql1%2Fuploads%2Fgit-blob-ffb9c16734912eadd9e2bfda6e67c645743f02dd%2F7a9c43b6fcc338c354967b62eafd25468ab17cdc98b4d135798279c8c70b16cc.png?alt=media)

### Cortex XSOAR 8 SaaS indicator retention limits

Unlike incidents, indicators in Cortex XSOAR will not have a time limit. We will limit the number of indicators per tenant as follows:

| License                | Indicators                   |
| ---------------------- | ---------------------------- |
| XSOAR + TIM            | Up to 100 million indicators |
| XSOAR (No TIM license) | Up to 3 million indicators   |

#### When will Palo Alto Networks enforce Cortex XSOAR 8 SaaS indicator limits?

Indicator retention enforcement is planned for 2025.

#### Can I increase my Cortex XSOAR indicator limit?

Customers with no TIM license can buy a TIM license and have up to 100 million indicators on their tenant. The number of indicators can’t exceed 100 million per tenant.

#### How does Cortex XSOAR delete indicators after reaching the limit?

The indicators will be deleted from older to newer (FIFO). Indicators that are linked to open incidents will not be deleted.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-retention-policy/cortex-xsoar-8-retention-policy-faqs/readme.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
