Skip to main content

Tenant logs

Atlan can help you understand the events that occur in your tenants, including user and administrative actions. Learn more about logging and retention as follows:

Tenant logs

Note the following:

  • Load balancer logs for Azure and GCP tenants are currently not enabled.
  • AuditSearch and SearchLog records are persisted forever in Elasticsearch. The 30-day retention period pertains to application logs written to logging Elasticsearch.
  • An example of block storage mentioned below is Amazon Elastic Block Store (EBS) for AWS.

Production tenants

Log typesRetentionStorageAWSAzureGCP
Active tenant overall backup15 daysObject storage
Offboarded tenant overall backupAWS - 30 days, Azure and GCP - 15 daysObject storage
Load balancer logs30 daysObject storage
Audit - user events60 daysPostgreSQL
Audit - admin eventsUnlimitedPostgreSQL
Application logs30 daysElasticsearch and object storage
Workflow logs90 daysClickHouse
Workflow artifacts180 daysObject storage
Application metrics60 daysVictoriaMetrics (block storage)

Proof of value (POV) tenants

Log typesRetentionStorageAWSAzureGCP
Active tenant overall backup15 daysObject storage
Offboarded tenant overall backupAWS - 3 days, Azure and GCP - 15 daysObject storage
Load balancer logs30 daysObject storage
Audit - user events60 daysPostgreSQL
Audit - admin eventsUnlimitedPostgreSQL
Application logs30 daysElasticsearch and object storage
Workflow artifacts180 daysObject storage
Application metrics60 daysVictoriaMetrics (block storage)

Atlan logs

ServiceTypeLogging pipelineDestination
HeraclesapplicationFluent BitS3
Argoapplication, serverArgo, Fluent BitS3
Atlasapplication, audit, perfFluent BitS3
NumaflowapplicationFluent BitS3
Kube eventsapplicationFluent BitS3
Wisdomapplication, auditFluent BitS3
ChronosapplicationFluent BitS3
RedisapplicationFluent BitS3
Kongapplication, auditFluent Bit, PostgreSQL, Keycloak REST APIS3
KeycloakapplicationFluent BitS3
ElasticsearchapplicationFluent BitS3
CassandraapplicationFluent BitS3
HekaapplicationFluent BitS3
Pgpoolapplication, serverFluent BitS3
KafkaeventsFluent BitS3

Cloud storage lifecycle

The cloud storage created for each tenant has its own lifecycle. The lifecycle policy is attached to paths in the cloud storage. The lifecycle policy applied to a production tenant is as follows:

Amazon Web Services (AWS)

Lifecycle policyPathAction
DeleteClusterLogsAfter30Dayslogs/Expires
DeleteArgoArtifactsAfter180Daysargo-artifacts/Transitions to S3 Glacier Flexible Retrieval, then expires
DeleteArgoBackupAfter15Daysbackup/argo/Expires
DeleteAltanScheduleQueryargo-artifacts/default/schedule-query/Expires
DeletePostgresBackupAfter15Daysbackup/postgres/Expires
DeleteRedisBackupAfter15Daysbackup/redis/Expires
DeleteCassandraBackupAfter15Daysbackup/cassandra/Expires
DeletePrometheusBackupAfter15Daysbackup/prometheus/Expires
DeleteALBLogsAfter30DaysAWSLogs/Expires

Microsoft Azure

Lifecycle policyPathAction
DeleteClusterLogsAfter30Dayslogs/Delete
DeleteArgoArtifactsAfter180Daysargo-artifacts/Moves to archive after 90 days and delete after 180 days
DeleteArgoBackupAfter15Daysbackup/argo/Delete
DeletePostgresBackupAfter15Daysbackup/postgres/Delete
DeleteRedisBackupAfter15Daysbackup/redis/Delete
DeleteCassandraBackupAfter15Daysbackup/cassandra/Delete
DeleteAltanScheduleQueryargo-artifacts/default/schedule-query/Delete if blobs not modified in 1 day
DeleteSparkEventLogsAfter15Daysspark-event-logs/Delete

Google Cloud Platform (GCP)

Lifecycle policyPathAction
DeleteClusterLogsAfter15Dayslogs/Delete
DeleteArgoArtifactsAfter180Daysargo-artifacts/Archive
DeleteArgoArtifactsAfter270Daysargo-artifacts/Delete
DeleteArgoBackupAfter3Daysbackup/argo/Delete
DeletePostgresBackupAfter3Daysbackup/postgres/Delete
DeletePrometheusBackupAfter3Daysbackup/prometheus/Delete
DeleteRedisBackupAfter3Daysbackup/redis/Delete
DeleteScheduleQueryAfter1Dayargo-artifacts/default/schedule-query/Delete
DeleteSparkEventLogsAfter15Daysspark-event-logs/Delete
DeleteCassandraBackupAfter3Daysbackup/cassandra/Delete