Log Management and Retention Periods: A Reference Matrix
Log retention rests on three tiers: hot (0-90 days), warm (3-12 months), cold (1-10 years). The period is set by regulation, threat hunting and evidence value. A log lifecycle infographic, a log type/retention reference matrix, policy building steps and FAQs.
Quick answer: Log retention is a security discipline that decides how long and how you keep the records systems produce (logins, errors, transactions, security events). A practical rule rests on three tiers: the hot tier (0-90 days) is kept fast to access for live search, detection and live SIEM queries; the warm tier (3-12 months) is archived at medium speed for incident investigation and compliance audit; the cold tier (1-10 years) is kept in long term, cheap and immutable archive for forensic/legal evidence and regulation. Three things set the retention period: legal/regulatory obligation, threat hunting need (because attackers can stay undetected for months) and evidence value; of these three, the longest one wins. Two critical principles: logs must be kept immutable (WORM) because an attacker's first act is to clear logs to erase their tracks; and no logs means no incident · that is, short retention means a blind spot into the past. Correct log retention is the foundation of detecting a breach and proving it in court.
In a cyber incident investigation, the most common sentence is: "There are no logs for that date." Logs are the only evidence of what happened; but if kept too briefly, by the time the attack is noticed the records are already gone. This guide gathers log retention, from tiers to periods, from regulation to evidence value, into a single reference with world class clarity.
Log lifecycle and retention tiers
The logic of the tiered approach is to balance cost and access: new logs in expensive but fast storage (for instant query), old logs in cheap but slow archive (for rare but mandatory access). The goal is never to delete but to move to the right tier.
Log type and recommended retention reference matrix
| Log type | Why it matters | Typical retention |
|---|---|---|
| Identity/access (login, MFA) | Shows unauthorized access | 1-2 years |
| Security device (firewall, IDS) | Attack and scan traces | 6-12 months+ |
| Server/system (OS, service) | Compromise and error analysis | 3-12 months |
| Application/web | Business logic and exploit traces | 6-12 months |
| Database access | Data leak and privacy | 1-2 years+ |
| Audit trail | Compliance and legal evidence | 2-10 years per regulation |
Periods vary by country, sector and regulation; the above are common starting values. For logs containing personal data, KVKK must be considered for both the basis of retention and the obligation to delete.
Steps to build a log retention policy
- Inventory log sources. Which system produces which log, where? Find blind spots.
- Set retention periods. For each log type, regulation + threat hunting + evidence value; base it on the longest period.
- Centralize. Collect logs in a single SIEM/SOC platform; scattered logs cannot be analyzed.
- Make them immutable. WORM/append only storage; the attacker must not be able to delete a log, essential for digital evidence integrity.
- Tier and encrypt. Hot/warm/cold tiers; encrypt the archive.
- Synchronize time. A common clock across all systems via NTP; only then is a forensic timeline reliable.
Short log retention fundamentally cripples threat hunting and incident response; if the attacker entered months ago and there are no logs, you can never fully solve the incident.
Frequently asked questions
How long should I keep logs? There is no single number; it depends on log type, regulation and evidence need. General rule: choose the longest of regulation, threat hunting and evidence value. For many security logs, 6-12 months live then archive is a reasonable start.
Why should I not delete logs immediately? Because attacks are often noticed months later. If logs are kept briefly, by the time you investigate the breach the evidence is already gone. Logs also carry evidence value in court.
Why must logs be kept immutable? Because one of an attacker's first goals is to delete or alter logs to cover their tracks. Immutable (WORM) storage guarantees the log was not tampered with afterward and preserves evidence value.
How is log retention related to privacy law? Two ways: some logs must be kept for security and accountability, but logs containing personal data must also be kept only for a purpose limited period and securely deleted when it expires. The balance is set with a clear retention and disposal policy.
Sources
- NIST SP 800 92, Guide to Computer Security Log Management: https://csrc.nist.gov
- CISA, Logging Best Practices: https://www.cisa.gov
- OWASP, Logging Cheat Sheet: https://cheatsheetseries.owasp.org
- ENISA, Log Management: https://www.enisa.europa.eu
For log management, a central SIEM, immutable archive and a retention policy, contact DSET. From our Ankara Hacettepe Teknokent laboratory we provide cybersecurity, SOC, KVKK compliance and digital forensics services.
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.