# SIEM Timeline data persistence and retention

**URL:** <https://discuss.elastic.co/t/siem-timeline-data-persistence-and-retention/212344>\
**Category:** SIEM\
**Created:** [December 18, 2019, 2:14pm UTC](https://discuss.elastic.co/t/siem-timeline-data-persistence-and-retention/212344 "2019-12-18T14:14:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [December 18, 2019, 2:14pm UTC](https://discuss.elastic.co/t/siem-timeline-data-persistence-and-retention/212344/1 "2019-12-18T14:14:13Z")

</div>

Playing a bit with SIEM App and wondering where are Timeline stored and how to possibly control their retention?

Don't seem to find any godd system index candidates for this...

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [December 18, 2019, 9:13pm UTC](https://discuss.elastic.co/t/siem-timeline-data-persistence-and-retention/212344/2 "2019-12-18T21:13:27Z")

</div>

Hi stefws,

The Timeline is stored as part of the saved objects API and will be part of your `.kibana` index with the other saved objects such as saved queries. The retention time is going to be what that index retention time is which by default should be forever, unless someone has manually changed it.

At the moment you can view the objects outside the UI with either the Kibana REST API directly and something like CURL:  
[https://www.elastic.co/guide/en/kibana/master/saved-objects-api.html](https://www.elastic.co/guide/en/kibana/master/saved-objects-api.html)

Or if you're curious to take a look and have access to the `.kibana` index from dev tools you can query it as well. It is stored as these saved object types:

siem-ui-timeline  
siem-ui-timeline-note  
siem-ui-timeline-pinned-event

Example filter query to see object types:

```auto
GET /.kibana-*/_search
{
  "query": {
    "term" : { "type": "siem-ui-timeline" }
  }
}

```

or if your Kibana is locked down to where only REST is allowed to view your saved objects then it would be a CURL GET like this:

```auto
GET ${KIBANA_URL}/api/saved_objects/_find?type=siem-ui-timeline

```

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [December 19, 2019, 7:15am UTC](https://discuss.elastic.co/t/siem-timeline-data-persistence-and-retention/212344/3 "2019-12-19T07:15:20Z")

</div>

@Frank_Hassanabad Thanks for the info. It would properly be a good idea not to store such in .kibana but rather a specific .siem-timeline index so data can be managed separately and avoid to bloat .kibana too much ImHO.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 16, 2020, 7:15am UTC](https://discuss.elastic.co/t/siem-timeline-data-persistence-and-retention/212344/4 "2020-01-16T07:15:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
