Data Retention

This topic lists the Sysdig data retention policies. When a host or instance is no longer monitored, such as when the agent is uninstalled, the historical data continues to be retained for the times stated below.

Retention is limited by storage or time on an either/or basis.

Secure-only customers have two weeks of retention.

Sysdig Secure Retention Limits

ComponentRetention
Activity AuditKubernetes(kube) and Cmd (command) 90 days
Net (connection) and File (fileaccess) 7 days
Benchmarks90 days
Captures90 days
CSPM (Posture + Inventory)Resource data is refreshed every 24 hours when a posture evaluation is run.
Stale data (data from a failed scan because of a disconnected/removed agent, deleted cluster/account, or because the account lost its permissions) is shown for 7 days since the last scan.
Compliance data is stored in the backend for a year.
Pipeline Results
(cli-scan )
90 days
AND
Maximum of 5 tags per repository and a maximum of 5 different images per tag.
Policy Events1 million events or 90 days
Registry Scanning Results90 days
Reports14 days for all reports generated as a PDF, CSV, or JSON. This includes Vulnerability Management (VM), Compliance, and Posture reporting.
Runtime ReportingAvailable through VM reporting, this report includes workloads active when the report was created, as well as those terminated within the prior 24 hours.
Runtime viewWorkloads disappear from the Runtime view within 15 minutes after termination.
Workloads will never expire as long as they are running.
Sysdig Platform Audit90 days
Vulnerability Management Reports14 days
IAM Resources24 hours
Cloud Events90 days

If required, you can change the standard data retention settings using Sysdig REST API. Contact your Sysdig support team or professional services for assistance as there are a variety of storage and timeline implications to consider before making such a change.

Sysdig Monitor Metric Retention Limits

Metric Granularity (Samples)Retention
10s7 days
1m14 days
10m30 days
1h3 months
1d12 months

Sysdig Monitor Events Retention Limits

ComponentsRetention
All Events
The total event limit includes all event types: Infrastructure, Alert, Sysdig, and Custom events.
2,000,000 Total
Captures90 days
Custom Events30 days
Infrastructure Events30 days
Resolved Alert Events
Acknowledged Alert Events
30 days
Sysdig Platform Audit90 days
Unresolved Alert Events
Unacknowledged Alert Events
30 days