The saved search
Crowdstrike Devices Lookup - Cleanup runs every hour 29 minutes after the hour to remove old/stale device data from the kvstore. By default, it will remove any device that has not reported in longer than 2 days.
Even though a device may be removed, it will be re-added by the saved search
Crowdstrike Devices Lookup - Gen if it begins to send data again.
Update Search Macro
To change the retention period from the default 2 days, there is a search macro that will need to be updated.
- Navigate to Settings > Advanced Search > Search Macros.
- Set the "App" to
- Set the "Owner" to
- Click on
sa_crowdstrike_retentionto modify the definition.
- Set the definition to a valid time modifier.
Make sure to keep the quotes around the definition.
Update Search Schedule
It may also be necessary to update how often the cleanup search runs (default: hourly).
To update the default schedule perform the following steps:
- Navigate to Settings > Searches, reports, and alerts.
- Set the "App" dropdown to
- Set the "Owner" dropdown to
- Click "Edit" under actions for the search
Crowdstrike Devices Lookup - Cleanup
- Click "Edit Schedule" and update the schedule and necessary.