<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Archiving incident-related observability data beyond standard retention periods in Open Q&amp;A</title>
    <link>https://community.dynatrace.com/t5/Open-Q-A/Archiving-incident-related-observability-data-beyond-standard/m-p/303800#M40159</link>
    <description>&lt;DIV&gt;&lt;P&gt;In our organization, the SRE team has raised the following requirement:&lt;/P&gt;&lt;P&gt;When an incident occurs, they want to preserve all logs, traces, and metrics collected during the affected day so that they can continue investigating and performing data analysis for an indefinite period of time.&lt;/P&gt;&lt;P&gt;From an Observability perspective, what solutions could we provide to address this need?&lt;/P&gt;&lt;P&gt;We have tried to guide them towards using Dynatrace Notebooks, but their concern is that the underlying data may no longer be available after some time due to retention limits. What they are looking for is the ability to come back weeks or months later and still have access to the same data set in order to continue the investigation and analysis.&lt;/P&gt;&lt;P&gt;Has anyone faced a similar requirement? What would be the recommended approach in Dynatrace for long-term preservation of incident-related observability data?&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Wed, 26 Aug 2026 11:11:57 GMT</pubDate>
    <dc:creator>FranciscoMPalos</dc:creator>
    <dc:date>2026-08-26T11:11:57Z</dc:date>
    <item>
      <title>Archiving incident-related observability data beyond standard retention periods</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Archiving-incident-related-observability-data-beyond-standard/m-p/303800#M40159</link>
      <description>&lt;DIV&gt;&lt;P&gt;In our organization, the SRE team has raised the following requirement:&lt;/P&gt;&lt;P&gt;When an incident occurs, they want to preserve all logs, traces, and metrics collected during the affected day so that they can continue investigating and performing data analysis for an indefinite period of time.&lt;/P&gt;&lt;P&gt;From an Observability perspective, what solutions could we provide to address this need?&lt;/P&gt;&lt;P&gt;We have tried to guide them towards using Dynatrace Notebooks, but their concern is that the underlying data may no longer be available after some time due to retention limits. What they are looking for is the ability to come back weeks or months later and still have access to the same data set in order to continue the investigation and analysis.&lt;/P&gt;&lt;P&gt;Has anyone faced a similar requirement? What would be the recommended approach in Dynatrace for long-term preservation of incident-related observability data?&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 26 Aug 2026 11:11:57 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Archiving-incident-related-observability-data-beyond-standard/m-p/303800#M40159</guid>
      <dc:creator>FranciscoMPalos</dc:creator>
      <dc:date>2026-08-26T11:11:57Z</dc:date>
    </item>
    <item>
      <title>Re: Archiving incident-related observability data beyond standard retention periods</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Archiving-incident-related-observability-data-beyond-standard/m-p/303832#M40161</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/99997"&gt;@FranciscoMPalos&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Custom bucket retention — set up a dedicated bucket with longer retention and route incident data into it via a bucket assignment rule.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Export the incident slice out of Dynatrace entirely — this is what most teams actually end up doing for "indefinite." Run the DQL for that day/incident, dump logs/traces/metrics to CSV/JSON, push to S3 or wherever. We wired a Workflow to auto-trigger this the moment a problem gets flagged as an incident basically takes a snapshot and archives it outside the platform. That way retention policy stops mattering.&lt;/P&gt;&lt;P&gt;Notebooks alone won't save you — like you noticed, the notebook keeps the queries but not the underlying data once it ages out. If you want notebooks to stay useful months later, export the query results alongside them, don't rely on live re-execution.&lt;/P&gt;&lt;P&gt;Realistically: long-retention bucket for active incidents + auto-export workflow on incident creation is the combo that's held up for us.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sujit&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2026 04:56:27 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Archiving-incident-related-observability-data-beyond-standard/m-p/303832#M40161</guid>
      <dc:creator>sujit_k_singh</dc:creator>
      <dc:date>2026-08-27T04:56:27Z</dc:date>
    </item>
  </channel>
</rss>

