Extended Security Logging helps support security investigations by increasing the retention period for selected security logs within Haiilo's infrastructure.
By extending the retention period from 90 days to 180 days, Haiilo has more time to analyse relevant technical events when investigating a potential security incident. This can be particularly valuable when an incident is identified or reported long after the original events occurred.
This feature is available as part of the Advanced Security Add-on. Please contact your personal Account Manager for further information.
What is Extended Security Logging?
Extended Security Logging increases the retention period for selected security-relevant logs from 90 days to 180 days.
The extended retention period applies only to security logs created after the feature has been activated. Logs that were deleted before activation cannot be restored.
The additional retention period gives Haiilo more time to investigate relevant technical events when reviewing a potential security incident.
Which security logs are retained for longer?
Extended Security Logging applies to selected security logs generated within the production environment of the respective customer tenant.
These include, for example:
- Load balancer logs: Information about requests made to the Haiilo platform.
- Web application firewall logs: Information about requests inspected by the web application firewall.
- Tenant-scoped application logs, including:
- Gateway logs
- Backend logs
- Worker and job logs
- Application-level superadmin audit logs
Extended retention applies only to selected security-relevant logs. It does not mean that all technical, application, debugging, or operational logs are retained for 180 days. The logs available during an investigation depend on the affected services and the nature of the event.
What are the benefits of Extended Security Logging?
Some security incidents are not detected immediately. By retaining relevant security logs for a longer period, Haiilo can analyse technical events across a broader historical timeframe and investigate potential relationships between them.
This may help Haiilo:
- Investigate the timeline of a security incident.
- Review relevant requests and system events.
- Connect related events across a longer period.
- Conduct internal security analyses using a broader historical timeframe.
Extended Security Logging increases the amount of information that may be available during an investigation. It does not constitute continuous threat monitoring and does not guarantee the detection of a security incident or its complete reconstruction.
Do I need to configure anything?
Good news! No technical or administrative action is required from customers.
Haiilo activates and operates Extended Security Logging entirely within its managed SaaS infrastructure. No changes to your Haiilo configuration, systems, or integrations are required.
Where are the security logs stored?
Extended retention takes place within Haiilo's existing infrastructure. The security logs remain within the hosting region of the respective customer tenant.
Access is restricted to authorised Haiilo personnel and is permitted only for internal security analysis and as part of Haiilo's established security incident processes.
Can customers access the security logs?
No. Extended Security Logging does not provide an additional user interface, search capability, reporting functionality, export functionality, or direct access to the underlying security logs.
The logs are part of Haiilo's managed SaaS infrastructure and are used exclusively for internal security analysis. Communication relating to confirmed security incidents follows Haiilo's established security incident process.