Skip to main content

Purging Incidents

The abilityIncident toPurging purge incidents from OPSCOMfeature allows administrators to permanently remove outdated incident records from the system. ThisIts processprimary purpose is criticalto for maintainingmaintain data relevance, complyingcomply with organizational data retention policies, and optimizingoptimize overall database performance. This article outlinesis intended for OPS-COM administrators responsible for system maintenance and data lifecycle management.

Setup and Configuration

This feature requires specific administrative permissions to access the two methods for incident purging: individual deletion viatools.

incident

Admin searchSide: andAdministrators bulkmust deletion usinghave the Purge Incidents tool.

Setup & Configuration

To enable incident purging capabilities for an administrator, specific permissions must be granted.

  • You must add the Delete Incidents permission toenabled thewithin their specific administratoruser roles or individual administrators who require the abilityrole to purge incident records. Consult your system administrator or review the UserManage Roles and Permissions wiki articlepage for detailsdetailed instructions on modifying permissions.
  • access
levels.


User

Side: This feature is strictly a backend administrative tool and is not accessible to end-users on the portal.

Using this Feature

ThereAdministrators arecan twouse primarythe methodsfollowing forinstructions purgingto purge outdated incidents in OPSCOM:either individually through thea Incidentstandard Search,search or in bulk using the Purge Incidents tool.

Method 1: Using the Delete Incident Button (Individual Purge)

This method allows for the deletion of a specific incident after searching for it.

  1. Search for the incident you wish to purge using the standard Incident Search functionality.
  2. Once the incident details are displayed, observe the Delete Incident button.
    • The Delete Incident button will be available (active) only if the incident record is older than 7 years.
    • If the incident is less than 7 years old, the button will appear as "Delete Not Available" and will be greyed out, preventing deletion.
  3. If the button is active, click the Delete Incident button.
  4. Follow any subsequent prompts or confirmation messages to finalize the deletion of the incident.
Method 2: Using the Purge Incidents Tool (Bulk Purge)

This tool allows for searching anddedicated purging multiple incidents simultaneously based on specified criteria.utility.

  1. Click Tools, then Purge Incidents.
  2. The Search for Incidents to Purge screen will be displayed.
  3. Enter your search criteria into the available fields (e.g., date ranges, incident types, specific IDs).
    • The results displayed will be limited to the oldest 300 records that match your criteria.

      Note: When entering a value for "Number of Instances," the search field functions as "greater than or equal to." Therefore, supplying "1" might still display incidents with more than one instance.

  4. Review the displayed list of incidents.
  5. Enable the Delete checkbox next to each incident you wish to purge.
  6. Click the Purge Records button.
  7. A confirmation prompt will display. Click the Delete button within this prompt to confirm the action.

Best Practices & Considerations

  • Irreversible Action:
    • Warning: Purging incidents is a permanent and irreversible action.action. Once an incident is purged,successfully purged from the system, its data cannot be recovered. Exercise extreme caution and verify your selections before proceeding.confirming any deletion.

      Purging Individual Incidents

      1. Search for the specific incident you wish to purge using the standard incident search functionality.

      2. Review the incident details on the screen and locate the Delete Incident button.

      3. Click the Delete Incident button to initiate the removal.

      4. Follow the on-screen prompts and confirmation messages to finalize the deletion.

      The Delete Incident button will only be active and clickable if the incident record is strictly older than 7 years. If the incident is less than 7 years old, the button will display as Delete Not Available and remain disabled to enforce retention policies.

      Purging Incidents in Bulk

      1. Hover over Tools and click Purge Incidents to open the search screen.

      2. Enter your search criteria into the available fields, such as specific date ranges or incident types.

      3. Review the generated list, which is limited to displaying the oldest 300 records that match your criteria.

      4. Enable the Delete checkbox next to each specific incident you wish to purge.

      5. Click the Purge Records button.

      6. Click the Delete button within the confirmation prompt to finalize the action.

      When entering a value into the Number of Instances field on the bulk search screen, the system treats it as a "greater than or equal to" variable. For example, supplying the number 1 may still display incidents that have multiple instances attached to them.

      Available Actions and Buttons

      • Delete Incident: Click this button on an individual incident page to permanently remove that specific record from the database.

      • Purge Records: Click this button during a bulk search to simultaneously delete all selected records.


      Best Practices and Considerations

      • Conduct pre-purge reviews: It is highly recommended to perform a thorough review of all search results before executing a bulk purge. Because bulk deletions process multiple records at once, carefully verifying your selections ensures that no critical data is inadvertently removed.

      • Adhere to the 7-Yearyear Retentionretention Rulerule:: BeAdministrators must be aware of the system's built-in 7-year data retention policy for incidents.policy. Incidents cannot be purged using the individual button method if they are newer than 7 years.years, Theand the bulk purge tool will also primarily displayprioritizes older records.records to prevent premature data loss.

      • PermissionsRestrict Managementdeletion permissions:: Carefully manage the Delete Incidents permission. permission,Only grantinggrant itthis onlyaccess level to trustedtrusted, senior administrators who fully understand the irreversible nature of thedatabase action.purging.

      • AuditEstablish Traila comprehensive audit trail:: While the incident record itself is purged, ensureEnsure your organization has an appropriate audit trail or backup strategy if long-term historical access to all incident data is required for compliancelegal orcompliance. other purposes.

      • Pre-Purge Review: Before usingWhile the Purgeactive Incidents Tool, itrecord is highlycleared recommendedfrom the database to performoptimize aperformance, thoroughyou reviewmay ofstill theneed searchoffline resultsarchives andfor selectedfuture incidentsreference.

        to ensure no critical data is inadvertently removed.