Logging Best Practices

What is the Logging Lake?

 

Arizona State University's Logging Lake is the central Enterprise platform for managing log data from systems like servers, applications and network devices. It ensures that all log data is securely retained, governed under established rules and allows querying and visualization under appropriate access controls.

 

Who is the Logging Lake for?

The Logging Lake is designed to store log data generated by University systems, as mandated by the ASU Log Management Standard. Incoming log data is archived using secure, cost-efficient storage and can be accessed for additional capabilities through the Lighthouse. Whether supporting cybersecurity investigations, business and financial reporting, or engineering troubleshooting, the Logging Lake delivers valuable insights across multiple disciplines. Put simply, the Logging Lake is for everyone—whether you're managing IT infrastructure, securing data, supporting academic services or building research platforms, all University log data is required to flow through this central, enterprise-grade service.

Two layers of key services

The “Lake”: The Logging Lake is ASU’s designated central repository for all approved log data. Built on AWS S3, its primary functions include data retention, compliance and serving as a reliable and verifiable system-of-record. Log data ingestion can be configured in multiple ways, including using direct ingestion or tools like Cribl, available through the Observability Pipeline Platform, configured via a request to the Logging Lake Product Team.

 

The “Lighthouse”: The Lighthouse is a query and observability service that "illuminates" the data in the Lake, generating insights and metrics that drive impactful action. Its primary tool, OpenSearch, enables users to perform Natural Language Queries, create dashboards and set up alerts based on indexed log data. Data Stewards, who are responsible for documenting log use cases and managing requests, may request indexing in OpenSearch by providing an operational justification. The Logging Lake Product Team will assess these requests and provide consultation on ingesting logs into OpenSearch.

 

To get started

Visit ServiceNow to request Logging Lake access and OpenSearch access. For additional assistance or questions, please email [email protected] or join the product Slack channel, #et-logging-lake-support.