FAQ: Can Threat Stack remove Agents from our servers?
Threat Stack automatically revokes Agents that are offline for 24 hours in a row. Threat Stack disables the revoked Agent on your server, removes the agentID, and stops trying to connect to the Agent. As a result, the following occurs with Agent data:
- Data about the Agent itself permanently deletes from the Threat Stack Cloud Security Platform®.
- Alerts and events associated with alerts remain in the Threat Stack CSP.
- Event data not associated with alerts ages out of Threat Stack according to the data retention rules established on the Threat Stack CSP.