Views:

Create a log repository to organize collected log data according to specified ingestion and retention settings.

Procedure

  1. Go to Agentic SIEM & XDRData Source and Log ManagementThird-party log repositories.
  2. Click Create new log repository.
  3. Specify a name and description for the log repository.
  4. Select the desired ingestion and retention type.
    Note
    Note
    • Analytic ingestion: Ingests log data for analysis, correlation, and threat hunting, and supports both analytic and archival retention.
    • Archival ingestion: Ingests log data for infrequent queries or to meet compliance requirements, and only supports archival retention.
    • Archival retention: Stores data for compliance purposes or infrequent queries.
    • Analytic retention: Allows for frequent retrieval of log data for analysis, correlation, and threat hunting. The default retention period is 30 days.
  5. Click Create.
    The log repository is created and the log repository details drawer appears.
  6. Add one or more collectors to the log repository to begin ingesting and retaining log data from your third-party data sources.