Raw IDS events are stored by Alert Logic® for six months. This is also the case for any event that is appended to an incident that is escalated. However, while the raw event will expire at six months, the interpretive analysis (correlation analysis; manual analyst commentary) will remain in storage and accessible in the Alert Logic console in perpetuity for the life of that account.
Have more questions? Submit a request