We've got you covered
Logging of the log management system is often required for compliance purposes. Audit logs keep track of all the changes made to the Graylog deployment by end users. Graylog will record all state changes into the database, allowing for search, filter and exporting of all audit log entries.
In Graylog Enterprise version 3+, we can now enable the Audit log functionality to log to either a database or create the logs in a log file for collection. By default logging to the database is always enabled, and cannot be disabled.
During the configuration of the audit log, you can select the number of days you would like to retain the history for. This is fully adjustable based on your audit requirements, and is a per Graylog node setting allowing for customized retention periods.
Graylog activates the MongoDB audit log feature when the Enterprise functionality is enabled, and starts recording to the local database immediately. Every new action taken by administrators are recorded and put into a window for searching and exporting incase needed.
You can also add additional logging to a log file, with the Log4j2 audit log appender, which will output actions to a file on the system for collection or storage.