# Understanding the need for archiving

**URL:** <https://community.graylog.org/t/understanding-the-need-for-archiving/16660>\
**Category:** Graylog Central (peer support)\
**Created:** [August 4, 2020, 1:18pm UTC](https://community.graylog.org/t/understanding-the-need-for-archiving/16660 "2020-08-04T13:18:53Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sparrowhawk](https://avatars.discourse-cdn.com/v4/letter/s/ac8455/32.png) [@sparrowhawk](https://community.graylog.org/u/sparrowhawk)\
**Post date:** [August 4, 2020, 1:18pm UTC](https://community.graylog.org/t/understanding-the-need-for-archiving/16660/1 "2020-08-04T13:18:53Z")

</div>

Hello, we are using the free enterprise licence but have gone over the 5GB limit. I had been told that we needed the enterprise licence to be able to define a retention policy, is that the case? I need to keep logs for 12 months then delete them.

If I select set the index rotation period to P3M and the deletion as the action in the retention strategy menu, then set 4 as the maximum number of indices, won’t that keep 12 months worth of logs?

Thanks

---

<div class="post-metadata">

**Author:** ![Karlis](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/karlis/32/4798_2.png) [@Karlis](https://community.graylog.org/u/Karlis)\
**Post date:** [August 4, 2020, 1:48pm UTC](https://community.graylog.org/t/understanding-the-need-for-archiving/16660/2 "2020-08-04T13:48:47Z")

</div>

Not exactly. When there will be 4 full indices and new empty index will be created, the oldest one will be deleted. It means, you will have only 3 previous indices, 3 months each, and 1 current index. I recommend to set max 5 indices if you want to keep at least 12 months of logs.

---

<div class="post-metadata">

**Author:** ![sparrowhawk](https://avatars.discourse-cdn.com/v4/letter/s/ac8455/32.png) [@sparrowhawk](https://community.graylog.org/u/sparrowhawk)\
**Post date:** [August 4, 2020, 1:56pm UTC](https://community.graylog.org/t/understanding-the-need-for-archiving/16660/3 "2020-08-04T13:56:05Z")

</div>

Hi Karlis, thanks for the explanation. So do I need the archiving function provided by the enterprise licence in this case? It seems to me that I don’t unless I wanted to keep the log data indefinitely.

---

<div class="post-metadata">

**Author:** ![Karlis](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/karlis/32/4798_2.png) [@Karlis](https://community.graylog.org/u/Karlis)\
**Post date:** [August 4, 2020, 2:02pm UTC](https://community.graylog.org/t/understanding-the-need-for-archiving/16660/4 "2020-08-04T14:02:46Z")

</div>

No, if your storage space is enough to keep this amount of data. Archiving allows to keep data outside of Graylog database, i.e. on fileserver or detachable storage.

---

<div class="post-metadata">

**Author:** ![sparrowhawk](https://avatars.discourse-cdn.com/v4/letter/s/ac8455/32.png) [@sparrowhawk](https://community.graylog.org/u/sparrowhawk)\
**Post date:** [August 4, 2020, 2:17pm UTC](https://community.graylog.org/t/understanding-the-need-for-archiving/16660/5 "2020-08-04T14:17:06Z")

</div>

Thanks Karlis, that’s really helpful.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [August 18, 2020, 2:17pm UTC](https://community.graylog.org/t/understanding-the-need-for-archiving/16660/6 "2020-08-18T14:17:12Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
