DataBiosphere / azul

Metadata indexer and query service used for AnVIL, HCA, LungMAP, and CGP
Apache License 2.0
7 stars 2 forks source link

Increase retention of Elasticsearch domain error logs #5557

Closed dsotirho-ucsc closed 1 year ago

dsotirho-ucsc commented 1 year ago

Increase retention of Elasticsearch domain ES_APPLICATION_LOGS type logs to 180 days.

This ticket was prompted from the review of audit log retention #5078


hannes-ucsc commented 1 year ago

For demo, show retention in AWS console.

hannes-ucsc commented 1 year ago

Security review: This change increases the retention of Elasticsearch error logs to longer than what FedRAMP requires. We've determined that the resulting increase in storage volume is negligible. The logs are stored in CloudWatch will are encrypted server-side by default.

This change therefore increases our security posture.