The retention period varies depending on the type of logs.
The
audit logs that determine logins, changes, client arrivals/departures,
etc (e.g., what we'd normally use for HIPAA compliance) are normally
maintained for months. It depends on how much activity is going on in
the system, of course, but it is not unusual to find audit logs going
back 1 year or more.
The cloud logs that track
gateway activity, firewall events, IDS/IPS status, probes, etc. go back
at least a month but usually much more. We would normally expect to see
logs going back 3 months on an average system.
The
Round Robin Databases in the cloud that are used to generate the
monthly reports, and also contain information such as traffic volumes,
per-country alerts, etc rotate after 1 year, so they contain a year's
worth of data.
The detailed on-board gateway
and AP syslogs and diagnostic logs are usually maintained for at least 1
week, but frequently go back to 2-3 weeks (again, depending on
activity).