Setting retention windows that fit storage and investigation needs
How administrators balance investigation depth against disk and object-storage cost when planning log retention.
Retention is often copied from a vendor default and left untouched. That habit either burns budget on quiet debug noise or truncates history just when an incident needs a longer look-back.
Separate hot searchable retention from colder archive where your stack allows it. Keep the hot window long enough for routine incident reviews—often two to four weeks for many mid-size estates—and archive security-relevant streams longer under a clear policy.
Measure average daily ingest for two representative weeks before locking numbers. Page Spruceway’s alerting and retention reviews start from measured ingest, not brochure estimates.
Write retention decisions next to the business reason: operational triage, internal investigation, or a named compliance driver. Vague “keep forever” goals rarely survive the first storage invoice.
Revisit retention after major application launches or after adding verbose sources. Administrators should treat retention as a living schedule, not a one-time checkbox.