What Is a Log? Log Records, Log Management and Retention
A log is a timestamped record of what happens on a system. Log types, the syslog format, the log management lifecycle and personal data in logs, explained.

Short answer: A log is a timestamped record of the events that occur on a system or network. Each entry describes one event: when it happened, where it came from, who did it and what the result was. Operating systems, applications, firewalls and databases generate logs constantly. Log management covers collecting these records, storing them, analyzing them and disposing of them when their retention period ends. Whether you are chasing the cause of an outage or answering "who made this change?", the answer is in the logs.
What is a log?
The US National Institute of Standards and Technology (NIST) defines a log as a record of the events occurring within an organization's systems and networks. Its log management guide, SP 800-92, adds that logs are composed of log entries, each containing information about a specific event. Recording events this way is called logging.
Windows keeps three standard logs: Application, Security and System.
What is in a log entry?
OWASP's logging guidance says applications should record four things for every event:
- When: The date and time of the event.
- Where: The application and its version, and the server's hostname or IP address.
- Who: The user identity, and the client's IP address or device identifier.
- What: The type of event, its severity and a description; where possible, whether the action succeeded.
Types of logs
Logs are usually named after the layer that produces them:
- System logs: Events from operating system components, such as a driver that fails to load at startup. On Red Hat Enterprise Linux 8 and 9, rsyslog keeps log files in the /var/log directory, while systemd-journald stores records in a binary format.
- Application logs: Client requests and server responses, logins, transaction counts, and application startups, shutdowns and failures. The application developer decides which events to record.
- Security and audit logs: Successful and failed logon attempts, account creation and deletion, privilege assignments and the use of privileges. Windows keeps these events in the Security log.
- Network and firewall logs: Routers and firewalls permit or block traffic based on a policy; according to NIST, firewalls tend to generate more detailed logs than routers. VPN systems log login attempts, and web proxies record the URLs accessed through them.
- Access logs: A record of the requests a web server receives. The sample entry in the Apache documentation shows the client's IP address, user ID, time, request, status code and the size of the response.
Log formats: syslog and structured logs
RFC 5424 describes the syslog protocol, used to convey event notification messages. Published in March 2009, it obsoleted RFC 3164. The message header carries the priority (PRI), version, timestamp, hostname, app name, process ID and message ID. Here is the example from the RFC:
<34>1 2003-10-11T22:14:15.003Z mymachine.example.com su - ID47 - 'su root' failed for lonvick on /dev/pts/8The leading 34 packs the message's facility and severity into one number: the facility (4, security/authorization messages) is multiplied by 8 and the severity (2, Critical) is added, so 4 × 8 + 2 = 34. The RFC defines eight severity levels, from 0 (Emergency) to 7 (Debug). Over the traditional UDP transport, messages are sent to port 514 and, per RFC 5426, can be lost in transit without any notice.
A structured log stores the record as named fields instead of free text. In Google Cloud Logging, an entry whose payload is a JSON object is called a structured log, and you can query specific fields within it. OpenTelemetry recommends structured logs in production because their stable schema makes them straightforward to validate and parse. Logs without a consistent structure are much harder to analyze at scale.
Log management: from collection to disposal
NIST defines log management as the process for generating, transmitting, storing, analyzing and disposing of computer security log data. In practice it comes down to four steps:
- Collection and centralization: A log left on the machine that produced it can be deleted if that machine is compromised. Logs are therefore forwarded to a central log server and normalized, with each field converted to a consistent representation. NIST recommends synchronizing every host's clock to a common time source such as NTP; if clocks drift, the sequence of events cannot be reconstructed.
- Storage: When a log file is complete it is closed and a new one is opened (rotation); older files are compressed and archived. To show that archives have not been altered, a message digest is calculated for each file and stored securely.
- Analysis: Noise is filtered out and similar entries are aggregated. In what NIST calls event correlation, relationships between two or more log entries are identified.
- Disposal: Entries past their retention period are deleted. Logs that record activity of particular interest are kept anyway, which NIST calls log preservation.
We describe how these steps are built on a central platform on our centralized logging and telemetry page.
How long should logs be kept?
Two things set the retention period: regulation, and the need to investigate an incident after the fact. We cover which records must be kept for how long under Turkish rules in our log retention article.
The second need is measured by how long attackers go unnoticed. In Mandiant's M-Trends 2026, the global median dwell time is 14 days, but threats such as BRICKSTORM, planted on network appliances, stay hidden for nearly 400 days. According to the report, standard 90-day log retention policies leave organizations completely blind to the initial access vector and the full scope of these intrusions.
Logs and SIEM
Log management collects records, stores them and makes them searchable. A SIEM adds correlation and alerting on top: a run of failed logins followed by a successful one looks harmless entry by entry, but read together it can signal an attack. We explain how a SIEM and the SOC team that handles its alerts work together in our SIEM and SOC article.
On the operations side, logs are read alongside metrics: a metric shows that a service has slowed down or stopped, and the log usually tells you why. We cover how downtime is measured in our uptime article, and why alerts can arrive late in our Prometheus article.
Personal data in logs
Log entries often contain personal data: Apache's access log entry includes the client's IP address and user name. The KVKK (Türkiye's personal data protection law), Law No. 6698, defines personal data as any information relating to an identified or identifiable natural person. Which log fields fall under that definition is a question to settle with your legal team.
Among the general principles in Article 4 of the law are that data be relevant, limited and proportionate to the purpose of processing, and kept only for the period set by legislation or required for that purpose. Article 12 requires the technical and administrative measures needed to prevent unlawful access to personal data. On the technical side, OWASP recommends keeping passwords, session identifiers, access tokens, encryption keys and payment card data out of logs, and masking, hashing or encrypting them where they are needed.
Frequently asked questions
What is a log entry? A record of a single event on a system. It holds the event's time, its source, the user involved and the result in one line.
What does log mean in IT? A record of the events that happen on a system or network. Windows, for example, keeps separate Application, Security and System logs.
Where are log files stored? On Windows, events go to logs such as Application, Security and System. On Red Hat Enterprise Linux, rsyslog writes log files to the /var/log directory.
What is syslog? A protocol and message format used to convey event notification messages. Its current standard is RFC 5424.
Are log management and SIEM the same thing? No. Log management collects, stores and makes records searchable; a SIEM adds correlation on top and raises alerts on suspicious patterns.
Sources
- NIST, CSRC Glossary: log: definition of a log
- NIST, SP 800-92 Guide to Computer Security Log Management: log management, log types and functions (September 2006)
- Microsoft, Eventlog Key: the Application, Security and System logs
- Red Hat, How to find and interpret system log files on Linux: Linux log files
- Apache, Log Files: access log fields
- IETF, RFC 5424 The Syslog Protocol: the syslog message format (March 2009)
- IETF, RFC 5426 Transmission of Syslog Messages over UDP: UDP transport (March 2009)
- Google Cloud, Structured logging: structured logs
- OpenTelemetry, Logs: structured and unstructured logs
- OWASP, Logging Cheat Sheet: what to log and what to keep out of logs
- Mandiant, M-Trends 2026: dwell time and log retention (March 23, 2026)
- Law No. 6698 on the Protection of Personal Data: definition of personal data, general principles, data security (in Turkish)
- How we run this layer: log management