TL;DR: Telemetry storage is becoming a core operational control because teams need historical data for hunting, incident response, compliance, and eDiscovery while reducing SIEM spend, according to LimaCharlie. The governance issue is no longer whether to keep logs, but how to retain them in a normalized, searchable form without losing investigative reach.
At a glance
What this is: This is a blog post arguing that telemetry storage is an operational and governance requirement, not just a cost line item, because it supports hunting, investigations, compliance, and selective SIEM routing.
Why it matters: It matters because IAM, SOC, and security architecture teams need retained telemetry to investigate access abuse, reconstruct identity events, and reduce blind spots across endpoint, cloud, and application activity.
By the numbers:
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes.
👉 Read LimaCharlie’s analysis of why telemetry storage matters for cybersecurity organizations
Context
Telemetry storage is the retention of security-relevant data from endpoints, cloud services, applications, and identity systems so teams can investigate, correlate, and prove what happened after the fact. In this article, LimaCharlie frames that retention problem as both a security and cost challenge, especially when organisations want to reduce SIEM spend without losing the evidence needed for identity investigations and incident response.
The identity angle is real even though the post is broader than IAM. Logs from AWS, Google Cloud, 1Password, Microsoft 365, and code repositories are often the only durable record of credential use, access paths, and abuse patterns across human and non-human identities. That makes telemetry storage part of the control surface for access governance, not just a back-end archive decision.
Key questions
Q: How should security teams balance SIEM cost reduction with log retention?
A: Teams should reduce SIEM cost by filtering hot alerting data, not by discarding evidence. Keep full-fidelity telemetry in a searchable archive, then route only the events needed for real-time detection into expensive analytics. The retention model should still preserve identity, cloud, and application records needed for investigations, compliance, and eDiscovery.
Q: Why does telemetry storage matter for identity investigations?
A: Identity investigations often depend on audit trails that show who used which credential, from where, and in what sequence. If those records are missing or fragmented, analysts cannot reconstruct privilege abuse, third-party access, or compromised sessions with confidence. Stored telemetry preserves the evidence needed to validate account behaviour after the event.
Q: What breaks when organisations route too much telemetry away from searchable systems?
A: The main failure is evidentiary loss. Teams may still detect some activity in real time, but they lose the ability to prove chronology, scope, and root cause later. That weakens incident response, slows eDiscovery, and makes it harder to assess whether access abuse involved human or non-human identities.
Q: When should telemetry be retained outside the SIEM?
A: Telemetry should be retained outside the SIEM whenever it has future investigative value but is too expensive to ingest at scale. That usually includes cloud audit logs, endpoint records, SaaS access trails, and repository events. The key is to keep them searchable and policy-aligned, not merely archived in a dead store.
Technical breakdown
Why telemetry normalization matters for security investigations
Telemetry is only useful when teams can search, correlate, and preserve it in a consistent format. Raw logs often arrive with different schemas, time stamps, and field names across endpoints, cloud platforms, and SaaS tools, which slows investigations and weakens long-horizon threat hunting. Normalization makes it possible to compare events from identity systems, infrastructure, and application layers without re-parsing every source during an incident. That matters when the question is whether a credential, session, or account behaved normally over time.
Practical implication: store telemetry in a normalized format so identity and incident teams can query it without rebuilding context during an investigation.
How event-level routing changes SIEM economics
Event-level routing means organisations can decide which telemetry goes to expensive high-touch tools and which stays in lower-cost storage. The architectural trade-off is not about keeping less data overall, but about separating hot analytics from cold retention. That reduces SIEM ingestion cost while preserving the full record for later hunting, legal review, or retrospective detection rules. The risk is that routing decisions become de facto retention policy if teams do not define what must always remain searchable.
Practical implication: set routing rules around investigative value and retention requirements, not only around ingestion cost.
Why stored telemetry supports historical threat hunting and eDiscovery
A newly discovered threat often requires teams to look backwards, not just forwards. Stored telemetry lets analysts run detection rules against historical data to determine whether a known indicator of compromise, access pattern, or suspicious account action was already present before detection. The same retained evidence supports eDiscovery, insurance claims, and forensic reviews, where the burden is to prove sequence and scope rather than simply block future activity. For identity teams, this can be decisive when reconstructing privileged access or third-party access abuse.
Practical implication: keep enough historical telemetry to answer who accessed what, when, and from where after an access event is discovered.
Threat narrative
Attacker objective: The attacker’s objective is to remain hidden long enough to extend dwell time, frustrate investigation, and reduce the organisation’s ability to reconstruct abuse of credentials or privileged access.
- Entry begins when attackers exploit the lack of retained telemetry or incomplete logging to hide early access and lateral movement across cloud, identity, or endpoint systems.
- Escalation occurs when investigators cannot quickly reconstruct the sequence of credential use, privilege changes, or remote actions because relevant events were never stored or were routed away from searchable systems.
- Impact follows when incident response, compliance review, or eDiscovery is slowed, allowing attacker dwell time to increase and limiting the organisation’s ability to prove what happened.
NHI Mgmt Group analysis
Telemetry storage is now part of identity governance, not just observability. When access events, cloud logs, and application telemetry are fragmented, security teams cannot reliably reconstruct human or non-human identity activity after the fact. That weakens access reviews, incident response, and evidentiary workflows at the same time. Organisations should treat retention design as a control decision, not a storage preference.
Cost pressure often creates a telemetry retention blind spot. The temptation to reduce SIEM ingestion by discarding data upstream can create gaps precisely where identity investigations need continuity. The problem is not storage volume alone, but preserving the right records long enough to validate access, privilege use, and session behaviour. Practitioners should separate hot detection from durable evidence retention.
Event-level routing introduces a governance obligation around evidence preservation. If teams route only selected telemetry to expensive analytics, they must prove that excluded data remains available, searchable, and retained according to policy. Otherwise the organisation is making risk decisions implicitly, not explicitly. That is especially material where cloud logs, SaaS audit trails, and NHI activity must support regulatory and forensic requirements.
Telemetry sprawl creates a new form of operational debt. As attack surfaces expand across cloud, SaaS, code repositories, and remote work tools, the volume of identity-relevant events rises faster than many teams’ ability to retain and use them. The result is not just more data, but more places where key evidence can disappear. The practitioner response is to design for retention, correlation, and retrieval from the start.
What this signals
Telemetry retention is becoming an identity control plane issue. As organisations expand cloud, SaaS, and NHI estates, the security question shifts from whether data was collected to whether it can still be used to reconstruct access and privilege behaviour. That makes archived telemetry a prerequisite for effective identity governance, not a back-office convenience.
Evidence preservation is where many programmes will separate mature from immature operations. Teams that can retain, normalise, and query historical logs will recover faster from access abuse, privilege misuse, and third-party compromise. Those that optimise only for SIEM cost will keep creating blind spots in the exact places attackers exploit.
The practical next step is to align telemetry retention with identity risk, using durable search, traceable routing, and policy-based retention for systems that carry authentication, access, and session data. For teams working with workload access and privileged accounts, this is where operational resilience and identity governance start to overlap.
For practitioners
- Separate hot detection from durable retention Keep only high-value alerting data in the SIEM while preserving full-fidelity telemetry in a searchable archive for investigation, compliance, and eDiscovery. Define which event classes must never be dropped, especially identity, cloud, and privileged access logs.
- Set retention policy by investigative value Classify telemetry by how often it supports access reconstruction, incident response, or legal evidence. Use those classes to decide storage duration, indexing depth, and retrieval priority instead of applying one generic log retention rule.
- Preserve identity-rich audit sources Prioritise logs from AWS, Microsoft 365, Google Cloud, password managers, and code repositories because they often contain the only durable record of account use, token activity, and third-party access. These sources are essential when investigating NHI and human identity abuse.
- Test historical search before an incident Validate that analysts can query archived telemetry quickly enough to answer whether a suspicious credential, session, or privilege change existed before detection. If the archive cannot support that question, it is not operationally ready.
Key takeaways
- Telemetry storage is not just an IT cost issue, because it determines whether security teams can reconstruct identity activity after an incident.
- Routing data away from expensive analytics can save money, but only if the organisation keeps searchable evidence for later investigations and legal use.
- Teams that treat retention, normalisation, and retrieval as governance controls will investigate access abuse faster and with more confidence.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | DE.CM-7 | Telemetry retention supports continuous monitoring and event analysis across security operations. |
| NIST SP 800-53 Rev 5 | AU-6 | AU-6 addresses audit review and analysis, which depends on accessible telemetry. |
| CIS Controls v8 | CIS-8 , Audit Log Management | Audit log management is the core control area for telemetry retention and review. |
| MITRE ATT&CK | TA0007 , Discovery; TA0006 , Credential Access; TA0008 , Lateral Movement | Telemetry storage helps detect post-compromise discovery, credential abuse, and movement. |
Map retained logs to DE.CM-7 and ensure monitoring data remains available for retrospective analysis.
Key terms
- Telemetry Storage: Telemetry storage is the retention of security-relevant logs and events so teams can investigate incidents, validate behaviour, and meet retention obligations. In practice, it must preserve enough structure and searchability to support correlation across identity, endpoint, cloud, and application data.
- Event-Level Routing: Event-level routing is the practice of sending only selected telemetry to expensive analytics systems while keeping the rest in lower-cost storage. It helps control ingestion spend, but it only works safely when excluded data remains searchable and governed for future investigations.
- Normalized Telemetry: Normalized telemetry is log data that has been reshaped into common terms before analysis begins. For identity security, that means consistent actor, action, source, and context fields that support search, baselining, and incident triage across systems.
- Historical Threat Hunting: Historical threat hunting is the practice of searching archived telemetry for signs of compromise after a new threat, indicator, or abuse pattern becomes known. It depends on retention depth, data quality, and the ability to query old events without rebuilding the evidence store first.
What's in the full article
LimaCharlie’s full blog covers the operational detail this post intentionally leaves for the source:
- Event-level routing patterns for shifting low-value telemetry out of expensive SIEM pipelines
- The storage and retrieval model behind a full year of free telemetry retention
- Practical examples of which log sources security teams should keep searchable for IR and eDiscovery
- Why different stakeholder groups, including legal and operations, need the same telemetry differently
Deepen your knowledge
NHI Mgmt Group covers identity security, NHI governance, and agentic AI through independent research, practitioner guides, and the NHI Foundation Level course, the industry's only accredited NHI security programme. Explore the course if your programme needs a shared foundation for access governance and machine identity risk.
Published by the NHIMG editorial team on August 1, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org