In the documentation at https://docs.splunk.com/Documentation/ES/7.0.2/Admin/Changethreatintel under
Review the logic for retention
the document states, "The threat retention input runs every 24 hours by default"
If it runs every 24 hours by default, how do you change that behavior?
What process/search/whatever runs the threat retention input? Where is it defined? Can it be run manually?