Learn how to manage your discovered cloud data.
| Where Can I Use This? | What Do I Need? |
- Strata Cloud Manager
- Prisma AIRS
|
|
You can delete historical discovery data for cloud accounts while keeping
the accounts active and operational within Prisma Cloud. This feature addresses data
compliance requirements when you need to remove collected asset information, flow
logs, and audit logs without disrupting your security posture or removing the cloud
account from monitoring.
When you initiate discovery data deletion, the system validates your
request and checks for active firewall deployments. Prisma AIRS temporarily disables
monitoring for the account and marks it with a deletion-in-progress status while a
background process removes all associated data from storage systems. This process
removes asset data from discovery databases and log data from your monitoring
infrastructure. Manually-deployed firewalls continue to inspect traffic during this
process, ensuring continuous security coverage. Auto-deployed firewalls, however, do
not continue to inspect traffic; the data deletion process automatically deletes the
associated Terraform template which then deletes the firewall. Once deletion
completes, the account becomes inactive and no longer collects any data.
The deletion process runs asynchronously to avoid impacting system
performance. You cannot modify account settings or enable additional monitoring
features while deletion is in progress. The system maintains audit timestamps to
track when deletion was requested and completed, providing visibility into data
lifecycle management activities for compliance reporting purposes.
If you delete a Terraform template associated with an
auto-deployed firewall, Prisma AIRS deletes all firewall resources deployed by that
template.