Log Management FAQ
This FAQ answers common questions about Cloudaware Log Management (Conflux).
What Types of Logs Can Conflux Collect?
Conflux can collect cloud provider logs (API/audit, network, and access), host‑level logs (for example, Metricbeat, Filebeat, Winlogbeat, Packetbeat), identity and access logs (Okta, OneLogin, and others), network and security service logs (such as Cloudflare), and custom application logs via syslog, HTTPS/webhooks, or file collectors.
See also: Supported Log Sources
Does Conflux Support Custom or Application‑Specific Logs?
Yes. You can forward custom logs via syslog or HTTPS/APIs. Conflux treats these as first‑class sources so they can be searched, correlated with Cloudaware CMDB, and used in dashboards and alerts.
How Long Is Log Data Retained?
By default, Conflux keeps a hot window of two months plus the current month and automatically archives older data for long‑term retention (up to several years). Actual retention is agreed with your organization and may vary by environment or dataset.
Can I Access and Query Raw Log Data?
Yes. Access Conflux via Cloudaware Control Hub (Launcher) to search and filter raw events using flexible query syntax based on Lucene/Elasticsearch‑style expressions, including field filters, ranges, and free‑text search. Saved searches and dashboards help operationalize frequently used queries.
How Does Conflux Integrate With Other Cloudaware Modules?
Conflux underpins several other modules:
- Intrusion Detection (Wazuh) and Log Management (Conflux) both are available via Cloudaware Control Hub (Launcher) and send findings and telemetry into Kibana-based UI.
- Monitoring and alerting can use logs as a signal source.
- Vulnerability Management and Advanced Analytics can also rely on log‑derived datasets for evidence and reporting.
See Modules and Integrations for more details.
How Is Access to Logs Secured?
Conflux follows Cloudaware’s security model:
- SSO via SAML‑compatible identity providers (for example, Okta, Azure AD, and others).
- Role‑based access control and audit logging for user actions.
- Encryption in transit and at rest for log data.
Work with your Cloudaware administrators to map your roles and groups to appropriate access levels for Conflux.