how to preserve logs for a security investigation
A log-preservation playbook for security investigations: freezing retention, exporting to write-once storage, hashing evidence, snapshotting cloud trails, and maintaining chain of custody. Use at the start of any incident. Triggers: 'preserve logs', 'log retention incident', 'chain of custody'. Not for: routine log management or log analysis itself.
how to preserve logs for a security investigation
TL;DR
Logs get rotated, overwritten, and deleted on a schedule, and an investigation is worthless without them. The moment you suspect an incident, export the relevant logs to separate write-once storage, hash everything, and write down who touched what and when. Preservation is boring and it is the thing that saves the investigation.
how to preserve logs for a security investigationUse this when
- a security incident is suspected or confirmed
- you need evidence that will hold up for legal, insurance, or regulatory review
- log retention is about to age out data you need
- you want a preservation step in your IR runbooks
Not for this skill when
- you are setting up routine log retention policy (that is operations)
- you need to analyze the logs (that comes after preservation)
- there is no incident and you just want tidier storage
- you need forensic disk imaging specifically (related, but a different procedure)
Steps
- Freeze retention first. Pause auto-deletion and rotation for every system in scope. Tell your log platform admin "incident hold" and get a written confirmation. Every hour of delay is data aging out.
- Export to separate storage. Copy the relevant time range to a bucket with object lock or equivalent write-once storage, in an account the incident scope cannot reach:
aws s3 cp s3://app-logs/2026/10/04/ s3://incident-hold/case-2026-10-04/ --recursiveExpected: the copy completes with no errors. Verify the object counts match between source and destination.
- Hash everything. Generate SHA256 manifests for every exported file so you can prove later that nothing changed:
sha256sum /incident-hold/case-2026-10-04/* | tee /incident-hold/case-2026-10-04/MANIFEST.txtExpected: one hash per file, with the manifest stored alongside the evidence.
- Snapshot the cloud trails. Export CloudTrail Lake query results or the S3 archive for the window, plus VPC flow logs and the relevant SaaS admin audit exports. Cloud sources are easy to forget because they feel permanent; their retention still expires.
- Grab endpoint state before anyone reimages. Export the EDR telemetry for affected hosts, and take a disk image if the machine might hold malware. Reimaging without this step destroys evidence permanently.
- Start the chain of custody. Keep a simple log of who collected what, when, and where it is stored. A shared doc is fine. Gaps in this log undermine everything later if the evidence ever matters legally.
Variant: preserving logs when you suspect an insider
Limit who knows about the preservation. Use a need-to-know group, collect from admin-level sources the suspect cant reach, and keep the hold storage somewhere the suspect has no access. Tell HR and counsel early.
Variant: preserving SaaS logs with short retention
Some SaaS apps keep audit logs for days, not months. Export on day one, automate the export if the investigation will run long, and screenshot the retention settings so you can show what was available.
Variant: preserving on a shoestring budget
An encrypted external drive plus hash manifests is a legitimate chain of custody for a small team. Write-once cloud storage is better, but a documented local copy beats a perfect system you never set up.
Why this happens
Most log systems keep 30 to 90 days and attackers count on that. Without a deliberate preservation step, the evidence ages out while you are still scoping, and you end up investigating with half a timeline.
Edge cases and pitfalls
- Exporting huge ranges is slow. Prioritize the incident window first, then widen outward. A tight window preserved today beats a wide window that aged out.
- Make sure the hold storage is in a different account. A compromised admin with delete rights in the same account can destroy your preserved copies.
- Legal hold requirements may extend retention beyond your plan. Check with counsel before you let anything expire.
- Document time zones on everything. Every timestamp in the report should say UTC, or the timeline will confuse everyone who reads it.
- Dont analyze from the originals. Work from copies so the preserved evidence stays untouched.
Provenance
Resolved from the public thread: https://vectle.com/posts/pstcsl6EdNKbXnN2icp4Z0zA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.