Log management is the practice of collecting the event records, or logs, that servers, applications, network devices, cloud services and security tools produce, then storing them in one place where they can be searched, analyzed and kept for as long as required. Logs record who signed in, what changed, which connections were made and what errors occurred. Managed well, they are the main evidence for troubleshooting problems, investigating security incidents and showing auditors that controls are working.
At a glance
- Logs are timestamped records of events produced by systems, applications and devices.
- Log management covers collection, parsing, central storage, search, retention and secure deletion.
- It underpins security monitoring, troubleshooting, performance analysis and compliance evidence.
- Retention periods are set by regulation, contracts and investigation needs, and vary widely.
- Cost is usually driven by data volume, so deciding what to collect and how long to keep it matters.
What problem it solves
Most systems write logs, but by default they often stay on the device that produced them, in different formats, and many are overwritten after a short time. When something goes wrong, such as an outage, a suspicious sign-in or a ransomware attack, the evidence may be spread across dozens of systems or already deleted. Attackers also try to erase logs to cover their tracks.
Central log management solves that. Logs are copied off the source systems as they are created, stored where they can’t easily be altered, and kept long enough to be useful. Teams can search across every source at once to trace an event from start to finish. For compliance, it provides evidence that access is recorded and reviewed, which many frameworks and auditors ask for.
How it works
Collection. Agents on servers and endpoints, standard log forwarding from network devices, and connections to cloud and SaaS platforms send logs to a central system.
Parsing and normalization. Different formats are broken into consistent fields, such as time, user, source and action, so events from different systems can be compared.
Storage and retention. Logs are stored with access controls and, ideally, protection against tampering. Recent data sits in fast, searchable storage; older data often moves to cheaper archive storage until its retention period ends.
Search and analysis. Teams query logs to troubleshoot problems, investigate incidents and build dashboards and reports.
Downstream use. Log data feeds other tools: a security information and event management (SIEM) platform for threat detection, user and entity behavior analytics (UEBA) for spotting unusual behaviour, and application performance monitoring and observability tools for performance.
When it matters for buyers
- When an audit or compliance deadline is coming. Many frameworks expect logging, log review and defined retention.
- After an incident with missing evidence. If an investigation stalled because logs weren’t kept, central collection is the fix. Investigators in incident response (IR) rely heavily on them.
- When cyber insurers ask about monitoring. Questions about log retention and review are common.
- When moving to cloud and SaaS. Many platforms keep their own logs for a limited time, and some only offer longer retention or detailed audit logs on higher-priced plans.
- When log costs grow. Volume-based pricing makes collection choices a budget question. Our SIEM overview covers how log-based security platforms are priced.
Questions to ask vendors
- Which sources can you collect from out of the box, including our cloud and SaaS platforms?
- How is pricing calculated: by ingested volume, stored volume, sources or users?
- What retention options do you offer, and what does it cost to keep data searchable versus archived?
- How do you protect logs from being altered or deleted, including by administrators?
- How fast is search across large volumes and long time ranges?
- Can we filter or reduce low-value logs before they count toward pricing?
- If we leave, how do we export our logs, and in what format?
How it differs from a SIEM
Log management is the foundation: collecting, storing, searching and retaining logs. A SIEM sits on top of that foundation and adds security-specific work, correlating events across sources, applying detection rules and raising alerts for analysts. Many SIEM products include log management, and many log platforms add some security features, so product categories overlap. The useful distinction for a buyer is the job: if you need evidence, search and retention, log management may be enough; if you need threat detection and alerting, you need SIEM capabilities or a service that provides them.
