# How to apply log retention policies to Elastic SIEM

**URL:** <https://discuss.elastic.co/t/how-to-apply-log-retention-policies-to-elastic-siem/220796>\
**Category:** SIEM\
**Created:** [February 25, 2020, 8:42am UTC](https://discuss.elastic.co/t/how-to-apply-log-retention-policies-to-elastic-siem/220796 "2020-02-25T08:42:21Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![anon67583212](https://avatars.discourse-cdn.com/v4/letter/a/8e7dd6/32.png) [@anon67583212](https://discuss.elastic.co/u/anon67583212)\
**Post date:** [February 25, 2020, 8:42am UTC](https://discuss.elastic.co/t/how-to-apply-log-retention-policies-to-elastic-siem/220796/1 "2020-02-25T08:42:21Z")

</div>

Good morning,

I am doing some tests with the product and I have just come across something, at least inconsistent: you cannot apply granular log retention policies. I mean, if you want to apply a 30-day retention policy for logs coming from sourceA and 20-day, for example, for logs coming from sourceB, this is not possible because a single index (filebeat-release-date) is used. Am I right?

Exists some procedure or tip to apply diferent retention policy depending which is the source?

Many thanks.

---

<div class="post-metadata">

**Author:** ![vinu89](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vinu89/32/45939_2.png) [@vinu89](https://discuss.elastic.co/u/vinu89)\
**Post date:** [February 25, 2020, 9:19am UTC](https://discuss.elastic.co/t/how-to-apply-log-retention-policies-to-elastic-siem/220796/2 "2020-02-25T09:19:10Z")

</div>

hi,

is the source A and source B shares the same logstash configuration..

---

<div class="post-metadata">

**Author:** ![anon67583212](https://avatars.discourse-cdn.com/v4/letter/a/8e7dd6/32.png) [@anon67583212](https://discuss.elastic.co/u/anon67583212)\
**Post date:** [February 25, 2020, 9:46am UTC](https://discuss.elastic.co/t/how-to-apply-log-retention-policies-to-elastic-siem/220796/3 "2020-02-25T09:46:21Z")

</div>

No, they are different log sources .....

---

<div class="post-metadata">

**Author:** ![Ramicoh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramicoh/32/61017_2.png) [@Ramicoh](https://discuss.elastic.co/u/Ramicoh)\
**Post date:** [March 1, 2020, 10:06am UTC](https://discuss.elastic.co/t/how-to-apply-log-retention-policies-to-elastic-siem/220796/6 "2020-03-01T10:06:30Z")

</div>

If each source is written to its own index life cycle management policy, then each of them can have its own retention period.

Both should use the same prefix in their pattern, so that they would be visible to the SIEM app.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2020, 10:06am UTC](https://discuss.elastic.co/t/how-to-apply-log-retention-policies-to-elastic-siem/220796/7 "2020-03-29T10:06:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
