Graylog: Choosing a rotation strategy

This documentation is part of the Manage retention guide. You can view the complete guide here: How to configure log retention.

👋 Welcome to Stackhero documentation

Stackhero offers a fully managed Graylog cloud solution designed for speed and simplicity. You can:

  • Rely on an unlimited, dedicated SMTP email server included with your service.
  • Apply updates effortlessly with a single click, with no manual intervention required.
  • Use a custom domain name secured by HTTPS (for example, https://logs.your-company.com), providing your team with secure, direct access.
  • Benefit from strong performance and security on a private, dedicated infrastructure, with no shared resources or noisy neighbours.

Focus on your data, not your tools: you can get started with Stackhero's Graylog cloud hosting solution in just a few minutes.

Graylog offers three retention strategies:

  1. "Index time" defines the maximum duration for which messages are kept in each index, for example, 14 days per index.
  2. "Index message count" sets the maximum number of messages per index, for example, 20 million messages per index.
  3. "Index size" limits the maximum size of an index, for example, 40 GB per index.

You can select one of these strategies according to your specific requirements. For instance, choosing "Index time" ensures that you always have logs from the past X days.

Be sure to accurately estimate your disk space requirements.

For example, if you store 1 GB of logs per day and decide to keep logs for the past 365 days, you will need 365 GB of disk space. Remember to reserve additional space for system operations as well (see below).