Views:

Create a log repository to organize collected log data according to specified ingestion and retention settings.

Before you begin

To begin managing log data in a log repository, you must have one or more deployed Service Gateways with the Third-Party Log Collection service installed.

Procedure

  1. In Workflow and AutomationThird-Party IntegrationThird-Party Log Collection or Service ManagementData Source and Log ManagementThird-party log repositories, click Create New Log Repository.
  2. Specify a name and description for the log repository.
  3. Select the desired ingestion and retention type.
    • Ingestion types
      • Analytic: Ingests log data for analysis, correlation, and threat hunting
        • Supports both analytic and archival retention
      • Archival: Ingests log data for infrequent queries or to meet compliance requirements
        • Only supports archival retention
      Important
      Important
      • To ingest log data, you must allocate credits to Agentic SIEM.
      • You cannot change the ingestion type for a log repository after you create the repository.
    • Retention types:
      • Analytic: Allows for frequent retrieval of log data for analysis, correlation, and threat hunting. Default retention period: 30 days
      • Archival: Stores data for compliance purposes or infrequent queries
      Note
      Note
      Retention of data beyond the default period requires additional credits in Agentic SIEM.
  4. Click Create.
    The log repository is created and the log repository details drawer appears.
  5. Add one or more collectors to the log repository to begin ingesting and retaining log data from your third-party data sources.
    Important
    Important
    Ensure you have installed the Third-Party Log Collection service on your deployed Service Gateways in Service Gateway Management before adding collectors.
  6. Monitor your data ingestion and retention in Data Source and Log ManagementData usage and monitoring.