Modify ARP/AI snapshot retention periods on ASA r2 storage systems
If Autonomous Ransomware Protection with Artificial Intelligence (ARP/AI) detects abnormal activity on one or more storage units on your ASA r2 system, it automatically creates an ARP snapshot to protect the data. Depending on your storage capacity and business requirements, you might want to increase or decrease the default ARP snapshot retention period. For example, you might increase the retention period for business-critical applications to support longer data recovery windows or decrease it for noncritical applications to save storage space.
The default retention period for the ARP snapshot varies depending on the action you take in response to the abnormal activity.
| If you take this action… | ARP snapshots are retained by default for… |
|---|---|
Mark as false positive |
12 hours |
Mark as potential ransomware attack |
7 days |
Do not take immediate action |
10 days |
You can modify the default retention periods by using the ONTAP command line interface (CLI). See Modify options for ONTAP automatic snapshots for steps to change the default retention period.