TL;DR: Telemetry storage is becoming a core operational control because teams need historical data for hunting, incident response, compliance, and eDiscovery while reducing SIEM spend, according to LimaCharlie. The governance issue is no longer whether to keep logs, but how to retain them in a normalized, searchable form without losing investigative reach.
NHIMG editorial — based on content published by LimaCharlie: Why telemetry storage matters for cybersecurity organizations
By the numbers:
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes.
Questions worth separating out
Q: How should security teams balance SIEM cost reduction with log retention?
A: Teams should reduce SIEM cost by filtering hot alerting data, not by discarding evidence.
Q: Why does telemetry storage matter for identity investigations?
A: Identity investigations often depend on audit trails that show who used which credential, from where, and in what sequence.
Q: What breaks when organisations route too much telemetry away from searchable systems?
A: The main failure is evidentiary loss.
Practitioner guidance
- Separate hot detection from durable retention Keep only high-value alerting data in the SIEM while preserving full-fidelity telemetry in a searchable archive for investigation, compliance, and eDiscovery.
- Set retention policy by investigative value Classify telemetry by how often it supports access reconstruction, incident response, or legal evidence.
- Preserve identity-rich audit sources Prioritise logs from AWS, Microsoft 365, Google Cloud, password managers, and code repositories because they often contain the only durable record of account use, token activity, and third-party access.
What's in the full article
LimaCharlie’s full blog covers the operational detail this post intentionally leaves for the source:
- Event-level routing patterns for shifting low-value telemetry out of expensive SIEM pipelines
- The storage and retrieval model behind a full year of free telemetry retention
- Practical examples of which log sources security teams should keep searchable for IR and eDiscovery
- Why different stakeholder groups, including legal and operations, need the same telemetry differently
👉 Read LimaCharlie’s analysis of why telemetry storage matters for cybersecurity organizations →
Telemetry storage and SIEM cost pressure: what teams need to know?
Explore further
Telemetry storage is now part of identity governance, not just observability. When access events, cloud logs, and application telemetry are fragmented, security teams cannot reliably reconstruct human or non-human identity activity after the fact. That weakens access reviews, incident response, and evidentiary workflows at the same time. Organisations should treat retention design as a control decision, not a storage preference.
A question worth separating out:
Q: When should telemetry be retained outside the SIEM?
A: Telemetry should be retained outside the SIEM whenever it has future investigative value but is too expensive to ingest at scale. That usually includes cloud audit logs, endpoint records, SaaS access trails, and repository events. The key is to keep them searchable and policy-aligned, not merely archived in a dead store.
👉 Read our full editorial: Telemetry storage gaps are reshaping cybersecurity operations