Creating a Log Retention Policy

Matt Ruzicka matt at frii.com
Mon Aug 22 22:38:45 GMT 2005


Last year I attended a session at USENIX on system logging in which the
instructor (Marcus Ranum) discussed the importance of having a clearly
defined (and enforced) log retention policy.  From what I remember of this
portion of the lecture (the slides and my notes are lacking in details) he
stressed that this policy would help significantly in the case of
litigation, but it obviously would also give a solid policy for defining
expectations and maintaining consistency between servers.

A year later (*cough, cough*) I've started to compile ideas for this
policy, but am having a bit of trouble finding good guidelines to follow.

I was wondering if others currently had a clearly defined log retention
policy for their organization and, if so, how they went about creating it?

Thanks in advance for any feedback.

Matthew Ruzicka - Systems Administrator
Front Range Internet, Inc.
matt at frii.net - (970) 212-0728

Got SPAM?  Take back your email with MailArmory.  http://www.MailArmory.com


More information about the freebsd-isp mailing list