LOGBOOK

HELP

Quiz Entry - updated: 2026.09.17

Beyond "ship everything to one platform", what does a central logging setup have to get right?

Centralisation only pays off if the transport and the platform are secured, nothing sensitive is written in the first place, and retention periods are set deliberately for audit and data-protection rules.

Centralisation itself means shippers or agents on every system forwarding to one platform, so that an investigation is one query instead of twenty SSH sessions — and so that evidence survives the compromise or loss of the host that produced it.

But a central log platform is also a juicy target and a compliance liability, which is why three things travel with it:

  • Don't log secrets or personal data. Passwords, tokens, full card numbers and unnecessary personal data must never reach the log in the first place — redact at the source. Deleting them afterwards from an indexed, replicated, backed-up store is close to impossible.
  • Secure transport and access. Logs in flight get TLS; the platform itself gets authentication and authorisation, because read access to all logs is effectively read access to the whole estate.
  • Retention and compliance. Define how long each class of log is kept: data-protection law (GDPR / the Swiss revDSG) pushes down, audit and forensic requirements push up, and storage cost pushes down again. The answer differs per log class, so "keep everything for a year" is a decision, not a default.

Go deeper:

From Quiz: ITIA / IT Infrastructure Monitoring: Logging, Monitoring and Observability | Updated: Sep 17, 2026