Terminology Index
Glossary
2953 terms
Log Retention
How long logs are kept before deletion, set to balance investigative and compliance needs against storage cost. Too short and evidence of slow or past attacks is lost; too long and costs and risk grow.
Log retention defines the period logs are stored, driven by investigative needs (attacks may be discovered months later), compliance and legal requirements, and storage cost. Setting it well, often tiering recent logs in fast storage and older logs in cheap cold storage, ensures data exists when needed for detection, investigation, and audits without unbounded expense. Too-short retention is a common gap that lets dwell-time-heavy intrusions escape reconstruction.
Introduced in: Logging, Monitoring, and Telemetry
Examples
- Keeping logs long enough to investigate a months-old intrusion.
- Setting retention to meet a compliance requirement.
- Tiering older logs to cold storage to control retention cost.
