BitLyft AIR® Data Management Overview
BitLyft AIR® securely collects and manages log data from multiple connected systems to provide real-time visibility and long-term storage for your organization’s security events.
How Data Is Collected
BitLyft AIR® automatically ingests log events from various APIs across your connected services (e.g., Microsoft 365, Azure, Google Workspace, and others).
These logs are processed in real time and stored in two locations for different purposes:
1. Real-Time Search
Purpose: Enables fast searching, correlation, and alerting within BitLyft AIR®.
Storage Location: Search cluster managed by BitLyft.
Retention: Logs remain searchable for 7 to 30 days, depending on your BitLyft AIR® subscription SKU.
Lifecycle: After the retention period, logs are automatically removed from Search to maintain optimal performance and compliance with your plan’s storage limits.
2. Long-Term Retention (Amazon S3)
Purpose: Provides cost-efficient, long-term log storage for compliance and historical review.
Storage Location: A dedicated, secure Amazon S3 bucket managed by BitLyft.
Retention: Logs are stored for 7 to 365 days, depending on your BitLyft AIR® subscription SKU.