Start from investigation questions
A useful record answers who acted, on what object, from where, when, with what outcome and through which system.
NIST: an organizational process
NIST SP 800-92 treats log management as infrastructure and an ongoing process covering sources, transport, storage, analysis, roles and maintenance. A SIEM does not replace ownership, policy or trustworthy time.
CIS Control 8: collect, alert, review and retain
These four actions form a practical test. A source nobody reviews is only an archive; an alert without context is only noise.
Minimum architecture
- Consistent time and system identities.
- Protected delivery with loss detection and buffering.
- Separate operational search from long-term archive.
- Role-based access, administrator auditing and tamper protection.
- Masking rules for personal data, secrets and request content.
Retention follows the use case
Consider detection time, investigation, legal obligations, cost and the risk of accumulating sensitive data. Set retention by event class and measure source coverage, delay, parsing failures, alert noise and archive recovery.
Applicable requirements depend on jurisdiction, sector, data and organizational role. This engineering overview is not legal advice.

