Data Retention
Retention for ingested logs is set per log source, not once for the whole platform. Each source carries two values that together decide how long its logs remain available to you, and for how long they can be produced for an audit.
This is separate from the retention that applies to Universal Sensor telemetry. If you are looking for how long endpoint telemetry is kept, see Long Term Telemetry Retention (LTTR) and the comparison below.
The two storage tiers
Ingested logs are held in two tiers, described in more detail under Log Pipelines:
| Tier | What it is for | What it powers |
|---|---|---|
| Observability | Warm, queryable storage for investigation and search. | Reveal dashboards and Hunt Lab queries. |
| Compliance | Cheaper immutable archival storage, holding logs in their original format. | Audit, regulatory retrieval, and historical requests. |
Each tier has its own retention value on each log source, expressed in months.
What each retention value means
Observability months
How long the log stays queryable. For as long as a source's observability retention has not elapsed, its logs can be searched in Hunt Lab and will appear in Reveal dashboards.
Set to zero, observability storage is off for that source and its logs are not queryable. The interface shows this as Observability off.
Compliance months
A total age from the point of ingestion, after which the log is deleted. It is not added on top of the observability period. The interface labels it cumulative for this reason, and the onboarding conversation describes it as a cumulative deletion boundary.
So a source with a shorter observability value and a longer compliance value behaves like this: the log is queryable for the observability period, then remains retrievable from immutable archival storage until it reaches the compliance age, at which point it is deleted.
Set to zero, compliance storage is off for that source and no archival copy is kept. The interface shows this as Compliance off.
Because compliance retention is a total rather than an addition, a compliance value must exceed the observability value to extend anything. Setting the two to the same number does not add archival time beyond the queryable period.
Seeing the retention set on a source
Go to Settings > Integrations and find the log source. Each source summarises its retention in the form:
<months>mo Observability / <months>mo Compliance (cumulative)
with either half replaced by Observability off or Compliance off where that tier is set to zero.
A source that shows — has no retention set yet. Retention is not populated until it has been confirmed for that source, so a source still being onboarded will show a dash rather than a default.
Exceptions for particular fields
A source's retention has a default pair of values, and can additionally carry exceptions that apply different retention to logs matching a particular field. This is used where most of a source's volume needs only a short queryable window, but a subset carries a longer regulatory obligation.
Exceptions are configured alongside the source's default retention.
When retention is chosen
Retention is confirmed for each source as part of onboarding that source, rather than edited freely afterwards. The onboarding conversation proposes a retention policy, lets you reuse a policy already applied elsewhere in your estate, and asks you to confirm it before the source goes live.
To change the retention on a source that is already live, contact your Customer Success Manager or support@senseon.io.
Older global retention settings. Some appliances still expose retention fields in the API settings area that predate per-source retention. These are deprecated and are being removed. They do not govern how long your ingested logs are kept. The per-source values described on this page are the ones that apply.
How this differs from telemetry retention
Telemetry gathered by the Universal Sensor and logs brought in through log ingestion are retained by two different mechanisms. Asking "how long is my data kept" gives a different answer for each.
| Universal Sensor telemetry | Ingested logs | |
|---|---|---|
| Governed by | Long Term Telemetry Retention (LTTR) | Per-source observability and compliance months |
| Scope | Applies across your telemetry | Set independently on each log source |
| Queryable window | 30 days in hot storage by default | The source's observability months |
| Extended retention | Up to 12 months in warm storage with LTTR enabled | The source's compliance months, as a total age from ingestion |
| Changing it | Request LTTR from Support or your Customer Success Manager | Confirmed per source, changed via Support or your Customer Success Manager |
A common source of confusion is applying the 30-day telemetry figure to an ingested log source such as a firewall. The two are unrelated. A firewall log's availability is decided by the retention on that log source, which you can read from its row on the Integrations page.