<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best practices for Log Management in Grail: What is your bucket and retention strategy? in Log Analytics</title>
    <link>https://community.dynatrace.com/t5/Log-Analytics/Best-practices-for-Log-Management-in-Grail-What-is-your-bucket/m-p/303386#M1602</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;A title="This video" href="https://www.youtube.com/watch?v=FLWCyVSEjwM" target="_blank" rel="noopener"&gt;This video&lt;/A&gt; can be helpful to you.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
    <pubDate>Tue, 18 Aug 2026 07:48:21 GMT</pubDate>
    <dc:creator>AntonPineiro</dc:creator>
    <dc:date>2026-08-18T07:48:21Z</dc:date>
    <item>
      <title>Best practices for Log Management in Grail: What is your bucket and retention strategy?</title>
      <link>https://community.dynatrace.com/t5/Log-Analytics/Best-practices-for-Log-Management-in-Grail-What-is-your-bucket/m-p/303369#M1600</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;We are currently redesigning our Log Management architecture in Grail to optimize both query performance and storage costs.&lt;/P&gt;&lt;P&gt;Historically, we kept raw logs for long periods, but we are now moving to a strict maximum retention of 30 days for all log levels (DEBUG, INFO, WARN, ERROR, and FATAL). We are also planning to partition our buckets by cluster rather than keeping a massive single bucket, and we intend to leverage the "Retain with Included Queries" billing model since our retention fits the 10-35 day window.&lt;/P&gt;&lt;P&gt;I would love to hear how you are managing this in your own environments:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Bucket Strategy:&lt;/STRONG&gt; Are you partitioning your buckets primarily by cluster, by team, or by application?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Long-Term Data:&lt;/STRONG&gt; For business or audit reports that require historical data (1 year+), are you dropping the raw logs and relying entirely on log-based metrics extracted via OpenPipeline?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Access Control:&lt;/STRONG&gt; How are you managing IAM policies and Segments so that platform engineers maintain central governance while giving developers autonomy to query their own clusters?&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Any insights, challenges, or lessons learned from your implementations would be greatly appreciated!&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2026 17:59:05 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Log-Analytics/Best-practices-for-Log-Management-in-Grail-What-is-your-bucket/m-p/303369#M1600</guid>
      <dc:creator>Mateusbmo1</dc:creator>
      <dc:date>2026-08-17T17:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices for Log Management in Grail: What is your bucket and retention strategy?</title>
      <link>https://community.dynatrace.com/t5/Log-Analytics/Best-practices-for-Log-Management-in-Grail-What-is-your-bucket/m-p/303386#M1602</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;A title="This video" href="https://www.youtube.com/watch?v=FLWCyVSEjwM" target="_blank" rel="noopener"&gt;This video&lt;/A&gt; can be helpful to you.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2026 07:48:21 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Log-Analytics/Best-practices-for-Log-Management-in-Grail-What-is-your-bucket/m-p/303386#M1602</guid>
      <dc:creator>AntonPineiro</dc:creator>
      <dc:date>2026-08-18T07:48:21Z</dc:date>
    </item>
  </channel>
</rss>

