{"allowedRenditionsWidth":["320","480","640","768","960","1200","1440","1920"],"templateName":"base-page-template54","cssClassNames":"page basicpage summit-page","canonicalLink":"https://www.snowflake.com/en/observability/log-management/","robotsTags":[],"description":"Learn how log management works across collection, storage, analysis and retention. Explore best practices for managing log data at scale.","language":"en","title":"Log Management: Lifecycle and Best Practices | Snowflake","analyticsPageType":"homepage","analyticsCategory":"general","analyticsSubCategory":"","excludeFromAnalytics":false,":path":"/content/snowflake-site/global/en/observability/log-management",":hierarchyType":"page","isPasswordProtected":false,"analyticsContentTags":[],"analyticsEnabled":true,":mappedPath":"/en/observability/log-management/",":type":"snowflake-site/components/structure/page","coveoConfig":{"pipeline":"snowflake.com","apiKey":"xx335921a6-2a0a-40f2-a167-e390b4766c3d","organizationId":"snowflakecomputingproduction8neljofn","searchHub":"snowflake.com"},"analyticsDebugMode":false,"analyticsData":{"excludeFromAnalytics":false,"subCategory":"","pageType":"homepage","templateName":"base-page-template54","siteName":"snowflake","pageUrl":"/content/snowflake-site/global/en/observability/log-management","language":"en","category":"general","pageName":"Log Management: Fundamentals, Lifecycle and Best Practices","contentTags":[]},":items":{"root":{"columnClassNames":{"markup_editor_928258845":"aem-GridColumn aem-GridColumn--default--12","experiencefragment-banner":"aem-GridColumn aem-GridColumn--default--12","experiencefragment-header":"aem-GridColumn aem-GridColumn--default--12","responsivegrid":"aem-GridColumn aem-GridColumn--default--12","markup_editor_597730182":"aem-GridColumn aem-GridColumn--default--12","experiencefragment-footer":"aem-GridColumn aem-GridColumn--default--12","experiencefragment":"aem-GridColumn aem-GridColumn--default--12","modal_container":"aem-GridColumn aem-GridColumn--default--12","markup_editor":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","columnCount":12,":items":{"experiencefragment-banner":{"id":"experiencefragment-0b79813833","localizedFragmentVariationPath":"/content/experience-fragments/snowflake-site/language-masters/en/site/pushdown-banner/master/jcr:content","configured":true,":type":"snowflake-site/components/experiencefragment","xfModelPath":"/content/experience-fragments/snowflake-site/language-masters/en/site/pushdown-banner/master.xfmodel.json"},"experiencefragment-header":{"id":"experiencefragment-25bec65376","localizedFragmentVariationPath":"/content/experience-fragments/snowflake-site/language-masters/en/site/mega-nav-header/master/jcr:content","configured":true,":type":"snowflake-site/components/experiencefragment","xfModelPath":"/content/experience-fragments/snowflake-site/language-masters/en/site/mega-nav-header/master.xfmodel.json","languageNavPath":"/content/snowflake-site/global/en/observability/log-management.languagenav.json"},"responsivegrid":{"columnClassNames":{"flexible_column_cont_939100716":"aem-GridColumn aem-GridColumn--default--12","flexible_column_cont":"aem-GridColumn aem-GridColumn--default--12","flexible_column_cont_1158003461":"aem-GridColumn aem-GridColumn--default--12","flexible_column_cont_663228916":"aem-GridColumn aem-GridColumn--default--12","flexible_column_cont_912630531":"aem-GridColumn aem-GridColumn--default--12","flexible_column_cont_1398138236":"aem-GridColumn aem-GridColumn--default--12","flexible_column_cont_1786318617":"aem-GridColumn aem-GridColumn--default--12","flexible_column_cont_1467213961":"aem-GridColumn aem-GridColumn--default--12","flexible_column_cont_1377146023":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","columnCount":12,":items":{"flexible_column_cont":{"id":"flexible-column-container-1314040dfa","propertiesId":"hub-hero-breadcrumbs","type":"1-column","alignColumns":"top","containerMaxWidth":"extra-large","topPadding":"small","bottomPadding":"none","spaceBetween":"small","reverseOnMobile":false,"carouselOnMobile":false,"propertiesCSSClasses":"page-section","backgroundImageOption":"none","flexible_column_content_container_1":{"layout":"SIMPLE","id":"container-442f384fb4",":type":"snowflake-site/components/flexible-column-container/flexible-column-content-container",":items":{"breadcrumb":{"id":"breadcrumb-1b8768869a","items":[{"id":"breadcrumb-1b8768869a-item-e7ce355135","link":{"valid":true,"url":"/en/"},"active":false,"current":false,"title":"English",":type":"snowflake-site/components/structure/page","appliedCssClassNames":"summit-page"},{"id":"breadcrumb-1b8768869a-item-83b2e1a746","link":{"valid":true,"url":"/en/observability/"},"active":false,"current":false,"title":"Observability",":type":"snowflake-site/components/structure/page","appliedCssClassNames":"summit-page"},{"id":"breadcrumb-1b8768869a-item-7f4e133324","link":{"valid":true,"url":"/en/observability/log-management/"},"active":true,"current":true,"title":"Log Management",":type":"snowflake-site/components/structure/page","appliedCssClassNames":"summit-page"}],":type":"snowflake-site/components/breadcrumb"}},":itemsOrder":["breadcrumb"]},"isBlogPage":false,"isActiveTOC":false,":type":"snowflake-site/components/flexible-column-container","appliedCssClassNames":"snowflake-flexible-column-container-gray-10-bg"},"flexible_column_cont_939100716":{"id":"flexible-column-container-895913f08d","propertiesId":"hub-hero","type":"2-column-even","alignColumns":"center","containerMaxWidth":"extra-large","topPadding":"extra-small","bottomPadding":"extra-small","spaceBetween":"small","reverseOnMobile":false,"carouselOnMobile":false,"propertiesCSSClasses":"page-section","backgroundImageOption":"none","flexible_column_content_container_1":{"layout":"SIMPLE","id":"container-e52212fde1",":type":"snowflake-site/components/flexible-column-container/flexible-column-content-container","appliedCssClassNames":"snowflake-responsive-container-inner-padding-extra-small",":items":{"title_v2":{"id":"title-v2-1545e02705","additionalClasses":"hub-hero__headline","type":"heading1","lines":["Log Management: Fundamentals, Lifecycle and Best Practices"],":type":"snowflake-site/components/title-v2","appliedCssClassNames":"left-alignment"},"text":{"id":"text-a6cdac1600","additionalClasses":"hub-hero__subheadline","text":"\u003Cp\u003ELearn how log management works, from collection and storage to analysis and retention. Explore best practices for managing log data in modern cloud and distributed environments.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-size-regular text-color-text-05"},"container":{"additionalClasses":"hub-hero__authors","columnClassNames":{"content_chip":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","layout":"RESPONSIVE_GRID","columnCount":12,"id":"container-81f92fe84e",":type":"snowflake-site/components/container","appliedCssClassNames":"snowflake-responsive-container-inner-padding-small",":items":{"content_chip":{"id":"content-chip-b7efd4845b","cta":{"id":"cta","showOutboundIcon":false,"buttonLink":{"valid":true,"url":"/en/blog/authors/rashmi-singh/"},"linkTargetContentType":"GENERIC","linkType":"SNOWFLAKE_INTERNAL",":type":"snowflake-site/components/button","text":"Read bio"},"image":{"id":"image","isLcpImage":true,"src":"https://www.snowflake.com/adobe/dynamicmedia/deliver/dm-aid--e0aed8fd-d7a3-4b8b-9d19-1aec6c7c04ec/rashmi-singh.jpg?preferwebp=true&quality=85","alt":"Rashmi Singh","lazyEnabled":true,"width":"614","height":"791",":type":"snowflake-site/components/image"},"headline":{"id":"title","type":"heading5","lines":["Rashmi Singh","Product Marketing Manager, Observability, Snowflake"],":type":"snowflake-site/components/title-v2"},":type":"snowflake-site/components/content-chip"}},":itemsOrder":["content_chip"]}},":itemsOrder":["title_v2","text","container"]},"flexible_column_content_container_2":{"additionalClasses":"hub-hero__video-column","layout":"SIMPLE","id":"container-0bf1c9a52c",":type":"snowflake-site/components/flexible-column-container/flexible-column-content-container",":items":{"youtube":{"id":"embed-b66fa1112d","youtubeVideoId":"-1r1QxDrl2o","layout":"responsive","youtubeAspectRatio":"56.25","youtubeAutoPlay":false,"youtubeLoop":false,"youtubeMute":false,"youtubePlaysInline":false,"youtubeRel":false,"embeddableResourceType":"core/wcm/components/embed/v1/embed/embeddable/youtube","type":"EMBEDDABLE",":type":"snowflake-site/components/youtube"}},":itemsOrder":["youtube"]},"isBlogPage":false,"isActiveTOC":false,":type":"snowflake-site/components/flexible-column-container","appliedCssClassNames":"snowflake-flexible-column-container-gray-10-bg"},"flexible_column_cont_1398138236":{"id":"flexible-column-container-b7081bca39","propertiesId":"hub-hero-related-topics","type":"1-column","alignColumns":"top","containerMaxWidth":"extra-large","topPadding":"extra-small","bottomPadding":"medium","spaceBetween":"small","reverseOnMobile":false,"carouselOnMobile":false,"propertiesCSSClasses":"page-section","backgroundImageOption":"none","flexible_column_content_container_1":{"additionalClasses":"related-topics-outer-container border-top","layout":"SIMPLE","id":"container-a5addd8029",":type":"snowflake-site/components/flexible-column-container/flexible-column-content-container",":items":{"text_894059747":{"id":"text-56b663954d","additionalClasses":"seo-hub-hero__related-topic-label","text":"\u003Cp\u003ELearn More:\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-size-regular text-color-text-05"},"text":{"id":"text-0c44f16840","additionalClasses":"related-topics ","text":"\u003Cul\u003E\r\n\u003Cli\u003E\u003Ca href=\"https://www.snowflake.com/en/product/observe/\"\u003EObserve by Snowflake\u003C/a\u003E\u003C/li\u003E\r\n\u003Cli\u003E\u003Ca href=\"https://www.snowflake.com/en/product/observe/contact/\"\u003EContact Observe\u003C/a\u003E\u003C/li\u003E\r\n\u003C/ul\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-size-regular"}},":itemsOrder":["text_894059747","text"]},"isBlogPage":false,"isActiveTOC":false,":type":"snowflake-site/components/flexible-column-container","appliedCssClassNames":"snowflake-flexible-column-container-gray-10-bg"},"flexible_column_cont_663228916":{"id":"flexible-column-container-e989b855b0","propertiesId":"hub-body","type":"2-column-60-40","alignColumns":"top","containerMaxWidth":"extra-large","topPadding":"medium","bottomPadding":"medium","spaceBetween":"small","reverseOnMobile":false,"carouselOnMobile":false,"propertiesCSSClasses":"page-section","backgroundImageOption":"none","flexible_column_content_container_1":{"additionalClasses":"longform-content","layout":"SIMPLE","id":"hub-body-content",":type":"snowflake-site/components/flexible-column-container/flexible-column-content-container","appliedCssClassNames":"snowflake-responsive-container-inner-padding-medium",":items":{"callout__0":{"id":"text-705d93a7a2","additionalClasses":"callout callout--general","text":"\u003Cp\u003E\u003Cstrong\u003ELOG MANAGEMENT DEFINED\u003C/strong\u003E\u003C/p\u003E\n\u003Cp\u003ELog management is the discipline of handling log data throughout its entire lifecycle. It covers several stages that deal with how logs are generated, collected, transported, parsed, centralized, stored, analyzed and eventually retired.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-size-regular text-color-text-05"},"text__0":{"id":"text-9278129e72","text":"\u003Cp\u003EEvery application, service and infrastructure component generates logs. As organizations adopt cloud platforms, containers and distributed architectures, the volume of log data continues to grow. Without a structured approach, valuable operational information becomes difficult to search, retain and analyze.\u003C/p\u003E\r\n\u003Cp\u003ELog management provides the processes and architecture needed to turn raw log data into useful operational insight. It helps engineering teams investigate incidents, improve system reliability and maintain long-term visibility across complex environments. This guide explains how log management works, the technologies and practices it relies on, and how it supports modern \u003Ca href=\"https://www.snowflake.com/en/observability/\"\u003Eobservability\u003C/a\u003E.\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"title_what-is-log-management":{"id":"title-v2-da11a67f95","additionalClasses":"anchor-title anchor-title--what-is-log-management","type":"heading2","lines":["What is log management?"],":type":"snowflake-site/components/title-v2"},"text_what-is-log-management_0":{"id":"text-cf48cfc3c5","text":"\u003Cp\u003ELog management is the discipline of handling log data throughout its entire lifecycle. It covers several stages that deal with how logs are generated, collected, transported, parsed, centralized, stored, analyzed and eventually retired. A well-designed log management strategy gives engineering teams fast access to operational data without allowing storage costs or operational complexity to spiral as systems grow.\u003C/p\u003E\n\u003Cp\u003ELogs are also one of the three pillars of observability, alongside metrics and traces. They provide the event-level detail needed to investigate incidents and understand system behavior.  Metrics quantify system health over time and traces reveal how requests move through distributed services and logs. Treating logs as part of a broader observability strategy helps teams troubleshoot faster and improve application reliability.\u003C/p\u003E\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"figure_1":{"id":"figure_1","isLcpImage":false,"src":"https://www.snowflake.com/adobe/dynamicmedia/deliver/dm-aid--ee72192f-5900-4998-9948-f435bc759764/log-management-figure-1.png?preferwebp=true&quality=85","alt":"Three pillars of observability.","lazyEnabled":true,"width":"624","height":"196",":type":"snowflake-site/components/image"},"text_what-is-log-management_0_cont_figure_1":{"id":"text_what-is-log-management_0_cont_figure_1","text":"\u003Cp style=\"text-align: center;\"\u003E\u003Ci\u003EFigure 1: Three pillars of observability\u003C/i\u003E\u003C/p\u003E\r\n\u003Cp\u003EEvery modern system produces logs because every system records events as they occur. A log file contains individual log entries, each representing a timestamped record of an event. These events may include a successful user login, an API request, a database query, a configuration change or an application error. Together, they create a chronological history of how systems behave under real-world conditions.\u003C/p\u003E\r\n\u003Cp\u003EManaging this data becomes increasingly complex as organizations scale. Hundreds of services may generate millions of log entries every hour across multiple environments. Without a structured approach, important events become difficult to find and troubleshooting takes longer because engineers spend more time locating relevant information than analyzing it.\u003C/p\u003E\r\n\u003Cp\u003ELog management addresses these challenges by establishing a repeatable process for moving data through a log pipeline. Raw events are collected from their source and sent to a centralized destination. They are then parsed into structured fields, enriched with additional context and stored according to retention requirements. Logs are analyzed when needed and eventually archived or removed.\u003C/p\u003E\r\n\u003Cp\u003ESeveral foundational concepts appear throughout the rest of this guide. Log levels classify event severity using values such as DEBUG, INFO, WARN and ERROR. This helps teams separate routine operational messages from actionable issues. Log schemas establish a consistent structure for log fields across applications and services and make it possible to query, filter and correlate data efficiently. As organizations move from unstructured text toward structured logging, consistent schemas become essential for scalable log management.\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"title_types-of-logs-and-log-data-formats":{"id":"title-v2-e909f0e44e","additionalClasses":"anchor-title anchor-title--types-of-logs-and-log-data-formats","type":"heading2","lines":["Types of logs and log data formats"],":type":"snowflake-site/components/title-v2"},"text_types-of-logs-and-log-data-formats_0":{"id":"text-61a1306ec0","text":"\u003Cp\u003ENot all logs capture the same type of information. Different systems produce different categories of log data. Each of these categories serves a distinct operational purpose. An effective log management strategy brings these sources together so engineers can investigate issues across an entire environment instead of isolated components.\u003C/p\u003E\n\u003Cp\u003ECommon log types include:\u003C/p\u003E\n\u003Cul\u003E\n\u003Cli\u003E\u003Cstrong\u003EApplication logs,\u003C/strong\u003E which record application events such as requests, exceptions, transactions and business operations.\u003C/li\u003E\n\u003Cli\u003E\u003Cstrong\u003EServer and system logs,\u003C/strong\u003E which capture operating system activity, resource usage, hardware events and service status.\u003C/li\u003E\n\u003Cli\u003E\u003Cstrong\u003ENetwork logs,\u003C/strong\u003E which record traffic flowing through routers, switches, firewalls and load balancers.\u003C/li\u003E\n\u003Cli\u003E\u003Cstrong\u003ESecurity and audit logs,\u003C/strong\u003E which document authentication events, privilege changes, policy violations and other security-relevant activity.\u003C/li\u003E\n\u003Cli\u003E\u003Cstrong\u003ECloud and infrastructure logs,\u003C/strong\u003E which capture events from managed cloud services, containers, Kubernetes clusters, virtual machines and serverless workloads.\u003C/li\u003E\n\u003C/ul\u003E\n\u003Cp\u003EThe format of log data directly affects how easily it can be parsed and queried. Traditional systems often generate plain text or syslog records that require additional parsing before analysis. Modern applications increasingly produce JSON logs and other structured or semi-structured data formats, where important fields such as timestamps, request IDs, host names, error codes and the like are already separated into discrete attributes.\u003C/p\u003E\n\u003Cp\u003EThis shift reflects the broader move from unstructured to structured logging. Unstructured logs remain useful for human readability but require more processing before machines can search or analyze them. Structured logging stores event data in predictable fields and allows engineers to filter, aggregate and correlate logs much more efficiently.\u003C/p\u003E\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"figure_2":{"id":"figure_2","isLcpImage":false,"src":"https://www.snowflake.com/adobe/dynamicmedia/deliver/dm-aid--330ec245-7a0d-4275-b9ea-0431b9bbbf9d/log-management-figure-2.png?preferwebp=true&quality=85","alt":"Types of logs.","lazyEnabled":true,"width":"624","height":"269",":type":"snowflake-site/components/image"},"text_types-of-logs-and-log-data-formats_0_cont_figure_2":{"id":"text_types-of-logs-and-log-data-formats_0_cont_figure_2","text":"\u003Cp style=\"text-align: center;\"\u003E\u003Ci\u003EFigure 2: Types of logs\u003C/i\u003E\u003C/p\u003E\r\n\u003Cp\u003EConsistency is equally important. A shared log schema ensures that services record common attributes using the same field names and formats. Without a standard schema, querying logs across dozens or hundreds of services becomes unnecessarily complex.\u003C/p\u003E\r\n\u003Cp\u003EStructured logging deserves its own discussion because it influences nearly every stage of the log management lifecycle, from parsing and storage to analytics and observability. This dedicated guide to structured logging explores implementation patterns, schema design and practical recommendations for building queryable log data at scale.\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"callout_types-of-logs-and-log-data-formats_0":{"id":"text-380b20cef8","additionalClasses":"callout callout--general","text":"\u003Cp\u003ELog management brings together application, infrastructure, network and security logs in structured formats that support efficient search and analysis.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-size-regular text-color-text-05"},"title_how-log-management-works-the-log-lifecycle":{"id":"title-v2-56b45b1ab6","additionalClasses":"anchor-title anchor-title--how-log-management-works-the-log-lifecycle","type":"heading2","lines":["How log management works: the log lifecycle"],":type":"snowflake-site/components/title-v2"},"text_how-log-management-works-the-log-lifecycle_0":{"id":"text-cd2c422e34","text":"\u003Cp\u003ELog management follows a continuous lifecycle that transforms raw event data into actionable operational insight. Although implementations vary, most modern log pipelines follow the same sequence: generate, collect, ship or forward, parse and enrich, centralize and aggregate, store and retain, analyze and correlate, and finally retire data according to retention policies.\u003C/p\u003E\n\u003Cp\u003EThe lifecycle begins when applications, infrastructure, operating systems and cloud services generate log entries. Every event contributes another record describing how the system behaved at a particular moment.\u003C/p\u003E\n\u003Cp\u003EThe next stage is collection, where log agents or collectors capture data at its source. These tools prepare logs for transport without significantly affecting application performance. Collected logs are then shipped or forwarded through the log pipeline. Shipping moves logs into centralized storage for long-term analysis, whereas forwarding routes logs between intermediate systems before they reach their final destination.\u003C/p\u003E\n\u003Cp\u003EDuring parsing and enrichment, raw log lines become structured records. Fields such as timestamps, service names, request identifiers, geographic locations or deployment metadata are extracted or added. By doing this, future searches become significantly more effective.\u003C/p\u003E\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"figure_3":{"id":"figure_3","isLcpImage":false,"src":"https://www.snowflake.com/adobe/dynamicmedia/deliver/dm-aid--8e315a24-ff61-40f3-a1e3-3e3cfb1bdf6c/log-management-figure-3.png?preferwebp=true&quality=85","alt":"Log management lifecycle.","lazyEnabled":true,"width":"624","height":"120",":type":"snowflake-site/components/image"},"text_how-log-management-works-the-log-lifecycle_0_cont_figure_3":{"id":"text_how-log-management-works-the-log-lifecycle_0_cont_figure_3","text":"\u003Cp style=\"text-align: center;\"\u003E\u003Ci\u003EFigure 3: Log management lifecycle\u003C/i\u003E\u003C/p\u003E\r\n\u003Cp\u003ELogs are then centralized and aggregated into a single platform that consolidates telemetry across applications and infrastructure. Rather than investigating isolated systems, engineers can search across an entire environment from one location.\u003C/p\u003E\r\n\u003Cp\u003EAfter centralization, logs enter the storage and retention phase. Retention policies determine how long data remains available and storage tiers balance accessibility against cost through hot and cold storage strategies.\u003C/p\u003E\r\n\u003Cp\u003EWhen incidents occur, teams move into analysis and correlation. Queries, dashboards and investigations connect related events across services, often alongside metrics and traces, to identify root causes quickly. Finally, logs reach the retirement stage, where expired data is archived or deleted according to business, regulatory or operational requirements.\u003C/p\u003E\r\n\u003Cp\u003ECollecting logs is no longer considered the hardest part of log management. The greater challenge is retaining growing volumes of data without driving up costs or discarding information that may later become critical during troubleshooting, performance analysis or security investigations.\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"callout_how-log-management-works-the-log-lifecycle_0":{"id":"text-ff0dbbe346","additionalClasses":"callout callout--general","text":"\u003Cp\u003EThe log management lifecycle moves data from generation and collection through storage, analysis and retention to support operational and security investigations.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-size-regular text-color-text-05"},"title_collecting-shipping-and-forwarding-logs":{"id":"title-v2-3f2ceb1642","additionalClasses":"anchor-title anchor-title--collecting-shipping-and-forwarding-logs","type":"heading2","lines":["Collecting, shipping and forwarding logs"],":type":"snowflake-site/components/title-v2"},"text_collecting-shipping-and-forwarding-logs_0":{"id":"text-19758ce911","text":"\u003Cp\u003ELog management begins with reliable collection. Every application, server, container, network device and cloud service generates event data locally, but those logs provide limited value if they remain isolated. Collection and transport move log data from its source into a centralized platform where it can be searched and analyzed.\u003C/p\u003E\n\u003Cp\u003EA log collector or log agent runs close to the workload generating the data. These components monitor log files, operating system events or application output, then package that information for transmission through the log pipeline.\u003C/p\u003E\n\u003Cp\u003ETwo of the most widely adopted open source collectors are Fluentd and Fluent Bit. Fluentd offers a rich plugin ecosystem for collecting, transforming and routing logs across complex environments. Fluent Bit provides a lightweight alternative designed for containers, Kubernetes clusters, and resource-constrained systems. Both function as pipeline components that route log data into downstream storage and analytics platforms rather than acting as destinations themselves.\u003C/p\u003E\n\u003Cp\u003EAlthough often used interchangeably, log shipping and log forwarding describe different stages of transport. Log shipping refers to moving collected logs into centralized storage for indexing or analysis. Log forwarding focuses on routing or relaying logs between intermediate systems before they reach their final destination.\u003C/p\u003E\n\u003Cp\u003ECollection is also the best point to improve data quality and reduce unnecessary volume. Log filtering removes noisy or low-value events before they consume storage resources. Log enrichment adds useful metadata such as environment, region, application version, host information, deployment identifiers and the like, which makes later investigations significantly more efficient.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"callout_collecting-shipping-and-forwarding-logs_0":{"id":"text-9fa35f917c","additionalClasses":"callout callout--general","text":"\u003Cp\u003ELog collection captures events from applications and infrastructure and moves them through a pipeline to a centralized log management platform.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-size-regular text-color-text-05"},"title_parsing-and-structuring-log-data":{"id":"title-v2-b89a9bc244","additionalClasses":"anchor-title anchor-title--parsing-and-structuring-log-data","type":"heading2","lines":["Parsing and structuring log data"],":type":"snowflake-site/components/title-v2"},"text_parsing-and-structuring-log-data_0":{"id":"text-dc0b83d1e6","text":"\u003Cp\u003ERaw log lines are designed for humans to read, not for systems to analyze at scale. Log parsing converts unstructured or semi-structured records into discrete fields that can be filtered, queried, aggregated and correlated across services.\u003C/p\u003E\n\u003Cp\u003EParsing typically extracts information such as timestamps, request identifiers, usernames, IP addresses, status codes, error messages and more from each log entry. Techniques such as field extraction, grok patterns, and data normalization transform inconsistent log formats into predictable records that support reliable analysis.\u003C/p\u003E\n\u003Cp\u003EThe quality of downstream analytics depends heavily on how consistently applications generate logs in the first place. Structured logging simplifies parsing because applications write fields in predefined formats instead of embedding information inside free-form text. Less parsing work reduces operational complexity and improves query performance.\u003C/p\u003E\n\u003Cp\u003EA shared log schema reinforces this consistency across services. When every application records common fields using the same naming conventions and data types, engineers can search and correlate logs without creating custom parsing rules for every workload.\u003C/p\u003E\n\u003Cp\u003EParsing and structured logging are foundational practices for modern observability because they determine how efficiently organizations can search, analyze and retain growing volumes of telemetry.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"callout_parsing-and-structuring-log-data_0":{"id":"text-cd4f3eecbb","additionalClasses":"callout callout--general","text":"\u003Cp\u003ELog parsing extracts searchable fields from raw events, and structured logging improves query performance and data consistency.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-size-regular text-color-text-05"},"title_centralizing-and-aggregating-logs":{"id":"title-v2-8e5c0ff7f4","additionalClasses":"anchor-title anchor-title--centralizing-and-aggregating-logs","type":"heading2","lines":["Centralizing and aggregating logs"],":type":"snowflake-site/components/title-v2"},"text_centralizing-and-aggregating-logs_0":{"id":"text-4206508b8f","text":"\u003Cp\u003EAs organizations grow, logs become distributed across applications and infrastructure. Searching multiple systems during an incident slows investigations and makes it harder to understand what happened. Centralized logging solves this by bringing log data into a single platform where engineers can search and analyze it from one place.\u003C/p\u003E\n\u003Cp\u003EA centralized log management platform collects data from applications and infrastructure, and creates a consistent view of system activity. Instead of moving between individual tools, platform engineers, SREs and security teams work from the same operational data set. This shared view can make troubleshooting more efficient and help reduce duplicate data pipelines.\u003C/p\u003E\n\u003Cp\u003ELog aggregation complements centralized logging by combining related events into a more useful data set. Aggregation can summarize repetitive events or combine logs from multiple instances of the same service and make large data sets easier to interpret without removing valuable context.\u003C/p\u003E\n\u003Cp\u003EMany log management platforms rely on indexing to accelerate searches. Indexing improves query performance, but it also increases storage requirements and operational costs. As telemetry volumes grow, organizations often face a trade-off between fast search performance and the cost of retaining and indexing large volumes of log data.\u003C/p\u003E\n\u003Cp\u003ECentralized logging and log aggregation form the foundation for scalable observability. Once logs are available in a single location, engineering teams can correlate activity across systems instead of investigating isolated components.\u003C/p\u003E\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"figure_4":{"id":"figure_4","isLcpImage":false,"src":"https://www.snowflake.com/adobe/dynamicmedia/deliver/dm-aid--e544c18b-8d80-4e11-809c-a0db95ad4c2e/log-management-figure-4.png?preferwebp=true&quality=85","alt":"Illustration of centralized logging.","lazyEnabled":true,"width":"624","height":"196",":type":"snowflake-site/components/image"},"text_centralizing-and-aggregating-logs_0_cont_figure_4":{"id":"text_centralizing-and-aggregating-logs_0_cont_figure_4","text":"\u003Cp style=\"text-align: center;\"\u003E\u003Ci\u003EFigure 4: Illustration of centralized logging\u003C/i\u003E\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"callout_centralizing-and-aggregating-logs_0":{"id":"text-484825b7c5","additionalClasses":"callout callout--tip","text":"\u003Cp\u003ECentralized log management consolidates logs from multiple systems into one platform for faster search, analysis and troubleshooting.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-size-regular text-color-text-05"},"title_storing-retaining-and-rotating-logs":{"id":"title-v2-b84bcfb57b","additionalClasses":"anchor-title anchor-title--storing-retaining-and-rotating-logs","type":"heading2","lines":["Storing, retaining and rotating logs"],":type":"snowflake-site/components/title-v2"},"text_storing-retaining-and-rotating-logs_0":{"id":"text-9a6e80a468","text":"\u003Cp\u003EFor many engineering teams, storing logs becomes more challenging than collecting them. Log volume grows continuously as applications scale, which makes storage strategy an important part of any log management architecture. The goal is to retain valuable operational history without allowing storage costs to grow at the same pace.\u003C/p\u003E\n\u003Cp\u003EA log retention policy determines how long different types of logs remain available. Retention periods depend on operational needs and regulatory requirements. Production application logs may need to remain available for troubleshooting, whereas audit logs are often retained to satisfy compliance obligations.\u003C/p\u003E\n\u003Cp\u003ELog rotation manages the size of active log files by archiving or replacing them according to predefined policies. Rotation prevents local storage from filling unexpectedly and keeps systems running reliably. Compression can further reduce storage requirements by minimizing the space occupied by historical log files.\u003C/p\u003E\n\u003Cp\u003EMany organizations use data tiering to balance performance and cost. Frequently accessed logs remain in hot storage for fast queries, while older logs move to lower-cost cold storage where they can still be retrieved when needed.\u003C/p\u003E\n\u003Cp\u003EStorage architecture also has a significant impact on long-term retention costs. Traditional log management platforms often tightly couple storage and compute, which increases infrastructure costs as log volumes grow. As a result, organizations may reduce retention periods or archive data outside their observability platform to control costs. Platforms such as Observe by Snowflake separate storage from compute, which can give organizations greater flexibility in how they retain and analyze historical log data.\u003C/p\u003E\n\u003Cp\u003EAs observability data sets continue to expand, this approach can help organizations preserve historical context for troubleshooting, trend analysis and compliance-related workflows while managing retention requirements.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"callout_storing-retaining-and-rotating-logs_0":{"id":"text-755df52b16","additionalClasses":"callout callout--general","text":"\u003Cp\u003ELog storage strategies use retention policies, rotation and data tiering to balance accessibility, compliance and cost.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-size-regular text-color-text-05"},"title_analyzing-and-correlating-logs":{"id":"title-v2-63a734b148","additionalClasses":"anchor-title anchor-title--analyzing-and-correlating-logs","type":"heading2","lines":["Analyzing and correlating logs"],":type":"snowflake-site/components/title-v2"},"text_analyzing-and-correlating-logs_0":{"id":"text-62882c89f0","text":"\u003Cp\u003EThe value of log management comes from the ability to investigate problems and understand system behavior. Log analysis transforms raw event data into operational insight by helping engineers identify failures, diagnose performance issues and investigate unexpected behavior.\u003C/p\u003E\n\u003Cp\u003EAnalysis usually begins with searching or filtering log data to isolate relevant events. Engineers review application activity or infrastructure events to determine what happened before an incident occurred. The faster teams can locate relevant logs, the faster they can resolve production issues.\u003C/p\u003E\n\u003Cp\u003ELog analysis becomes more powerful when combined with log correlation. Correlation connects related events across applications and infrastructure using identifiers such as request IDs or trace IDs. Looking at correlated logs alongside metrics and traces gives engineers a more complete understanding of how an issue developed across distributed systems.\u003C/p\u003E\n\u003Cp\u003E\u003Ca href=\"https://www.snowflake.com/en/artificial-intelligence/\"\u003EArtificial intelligence\u003C/a\u003E is also changing how teams work with logs. Semantic search helps engineers locate relevant events without relying on exact keywords, and \u003Ca href=\"https://www.snowflake.com/en/fundamentals/large-language-model/\"\u003Elarge language models\u003C/a\u003E (LLMs) can summarize incidents or group similar errors to accelerate investigations.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"callout_analyzing-and-correlating-logs_0":{"id":"text-44f84dee30","additionalClasses":"callout callout--general","text":"\u003Cp\u003ELog analysis and correlation connect related events across applications and infrastructure to accelerate root cause analysis.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-size-regular text-color-text-05"},"title_log-management-vs-siem":{"id":"title-v2-7f1de55ca1","additionalClasses":"anchor-title anchor-title--log-management-vs-siem","type":"heading2","lines":["Log management vs. SIEM"],":type":"snowflake-site/components/title-v2"},"text_log-management-vs-siem_0":{"id":"text-f42549cfbf","text":"\u003Cp\u003ELog management and security information and event management (SIEM) are closely related, but they serve different purposes. Log management focuses on the complete lifecycle of operational log data. It covers collecting, storing and analyzing logs so engineering teams can troubleshoot applications and maintain long-term operational visibility.\u003C/p\u003E\n\u003Cp\u003EAn SIEM focuses on security. It analyzes log data to detect threats and generate alerts and helps security teams investigate suspicious activity in order to respond to potential incidents. The two technologies complement each other. A centralized log management platform provides the operational data and a SIEM applies security analytics to that information. Some organizations send selected logs from their central repository into a SIEM, whereas others perform SIEM-style analytics directly on their centralized log platform.\u003C/p\u003E\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"figure_5":{"id":"figure_5","isLcpImage":false,"src":"https://www.snowflake.com/adobe/dynamicmedia/deliver/dm-aid--0e10129e-30ea-49ba-a359-154509af29da/log-management-figure-5.png?preferwebp=true&quality=85","alt":"Log Management vs SIEM.","lazyEnabled":true,"width":"624","height":"403",":type":"snowflake-site/components/image"},"text_log-management-vs-siem_0_cont_figure_5":{"id":"text_log-management-vs-siem_0_cont_figure_5","text":"\u003Cp style=\"text-align: center;\"\u003E\u003Ci\u003EFigure 5: Log Management vs. SIEM\u003C/i\u003E\u003C/p\u003E\r\n\u003Cp\u003EThe distinction comes down to purpose. Log management ensures operational logs remain accessible throughout their lifecycle. An SIEM builds on that foundation to support threat detection and security investigations.\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"title_log-management-best-practices":{"id":"title-v2-cd545b9cb7","additionalClasses":"anchor-title anchor-title--log-management-best-practices","type":"heading2","lines":["Log management best practices"],":type":"snowflake-site/components/title-v2"},"text_log-management-best-practices_0":{"id":"text-73e0bb6826","text":"\u003Cp\u003EA successful log management strategy depends on consistent engineering practices rather than the tools used to collect or store data. Small decisions made during application development and infrastructure design have a significant impact on how useful logs remain during troubleshooting and long-term analysis.\u003C/p\u003E\n\u003Cp\u003ETeams should start by adopting structured logging and a shared log schema. Structured logs store information in consistent fields instead of free-form text. This makes it easier to query and correlate. A common schema extends that consistency across services, which reduces the effort required to analyze logs from different applications.\u003C/p\u003E\n\u003Cp\u003ELog quality also depends on how applications use log levels. Teams should reserve verbose logging for development and use production log levels deliberately to capture meaningful operational events. This approach reduces unnecessary noise without removing information that may become valuable during an investigation.\u003C/p\u003E\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"figure_6":{"id":"figure_6","isLcpImage":false,"src":"https://www.snowflake.com/adobe/dynamicmedia/deliver/dm-aid--9b6db1c7-c456-459d-a9fe-40d640f5fd7c/log-management-figure-6.png?preferwebp=true&quality=85","alt":"Log management best practices.","lazyEnabled":true,"width":"624","height":"365",":type":"snowflake-site/components/image"},"text_log-management-best-practices_0_cont_figure_6":{"id":"text_log-management-best-practices_0_cont_figure_6","text":"\u003Cp style=\"text-align: center;\"\u003E\u003Ci\u003EFigure 6: Log management best practices\u003C/i\u003E\u003C/p\u003E\r\n\u003Cp\u003ECentralizing logs early in the pipeline improves visibility across applications and infrastructure. Rather than searching multiple systems, engineers can investigate incidents from a single location and correlate events more efficiently. Managing log volume is equally important. Filtering low-value events at the source prevents unnecessary data from entering the pipeline. This not only reduces storage costs but also the amount of downstream processing required. Retention policies should then determine how long different categories of logs remain available based on operational needs or regulatory requirements.\u003C/p\u003E\r\n\u003Cp\u003ELogs should be treated as one component of observability rather than an isolated data set. Correlating logs with metrics and traces provides richer operational context and shortens the path to root cause analysis. Together, these practices can support a log management strategy designed to scale with modern applications while balancing performance, visibility and cost considerations.\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"callout_log-management-best-practices_0":{"id":"text-b874572a50","additionalClasses":"callout callout--general","text":"\u003Cp\u003EStructured logging, centralized collection, consistent schemas and retention policies improve log quality and operational visibility.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-size-regular text-color-text-05"},"title_why-manage-logs-on-observe":{"id":"title-v2-e28d8daf15","additionalClasses":"anchor-title anchor-title--why-manage-logs-on-observe","type":"heading2","lines":["Why manage logs on Observe"],":type":"snowflake-site/components/title-v2"},"text_why-manage-logs-on-observe_0":{"id":"text-b24d47dab7","text":"\u003Cp\u003E\u003Ca href=\"https://www.observeinc.com/why-observe\" target=\"_blank\"\u003EObserve\u003C/a\u003E by Snowflake is built for modern log management at cloud scale. Rather than treating logs as isolated records, Observe correlates them with metrics, traces and events to provide the context that engineers need to investigate production issues quickly. This unified view can help teams investigate potential root causes using connected operational context.\u003C/p\u003E\n\u003Cp\u003EObserve can ingest logs from a wide range of sources, including applications, cloud services, containers and \u003Ca href=\"https://opentelemetry.io/docs/what-is-opentelemetry/\" target=\"_blank\"\u003EOpenTelemetry\u003C/a\u003E pipelines. Observe can build relationships between logs, infrastructure and application services, which allows engineers to investigate incidents using connected operational data.\u003C/p\u003E\n\u003Cp\u003ELog management architectures take different approaches to indexing, storage and compute. Observe stores telemetry in Snowflake and uses its scalable storage and compute architecture. Depending on configuration and retention requirements, organizations can retain extended periods of log data while keeping historical telemetry available for investigation.\u003C/p\u003E\n\u003Cp\u003EObserve also preserves high-cardinality telemetry. Engineers use it to filter, group and investigate logs using rich contextual attributes such as customer IDs, Kubernetes pods, deployment versions, cloud regions and trace IDs. Preserving this context can help engineers investigate potential root causes of complex production issues across distributed systems.\u003C/p\u003E\n\u003Cp\u003EAI can also assist with investigations. Observe’s \u003Ca href=\"https://www.observeinc.com/product/ai-sre\" target=\"_blank\"\u003EAI SRE\u003C/a\u003E capabilities capabilities can use correlated telemetry to help summarize incidents, provide operational context and surface potential root causes through natural language interactions. By combining logs with metrics, traces and events, AI can use additional operational context to assist with incident response.\u003C/p\u003E\n\u003Cp\u003EBecause Observe runs on Snowflake, operational telemetry can be analyzed alongside other relevant data in Snowflake. This helps teams connect operational and business context. It can further enable engineering teams to understand the technical and business context of production issues.\u003C/p\u003E\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"figure_7":{"id":"figure_7","isLcpImage":false,"src":"https://www.snowflake.com/adobe/dynamicmedia/deliver/dm-aid--c1d81379-a50a-48f8-9738-ef3796092cc0/log-management-figure-7.png?preferwebp=true&quality=85","alt":"Log management UI on Observe.","lazyEnabled":true,"width":"624","height":"412",":type":"snowflake-site/components/image"},"text_why-manage-logs-on-observe_0_cont_figure_7":{"id":"text_why-manage-logs-on-observe_0_cont_figure_7","text":"\u003Cp style=\"text-align: center;\"\u003E\u003Ci\u003EFigure 7: Log management UI on Observe\u003C/i\u003E\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"},"callout_why-manage-logs-on-observe_0":{"id":"text-458af5c8b5","additionalClasses":"callout callout--general","text":"\u003Cp\u003E\u003Cstrong\u003EKEY TAKEAWAY\u003C/strong\u003E\u003C/p\u003E\n\u003Cp\u003ELog management centralizes, stores and analyzes operational log data so engineering teams can troubleshoot systems, investigate incidents and maintain long-term visibility at scale.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-size-regular text-color-text-05"}},":itemsOrder":["callout__0","text__0","title_what-is-log-management","text_what-is-log-management_0","figure_1","text_what-is-log-management_0_cont_figure_1","title_types-of-logs-and-log-data-formats","text_types-of-logs-and-log-data-formats_0","figure_2","text_types-of-logs-and-log-data-formats_0_cont_figure_2","callout_types-of-logs-and-log-data-formats_0","title_how-log-management-works-the-log-lifecycle","text_how-log-management-works-the-log-lifecycle_0","figure_3","text_how-log-management-works-the-log-lifecycle_0_cont_figure_3","callout_how-log-management-works-the-log-lifecycle_0","title_collecting-shipping-and-forwarding-logs","text_collecting-shipping-and-forwarding-logs_0","callout_collecting-shipping-and-forwarding-logs_0","title_parsing-and-structuring-log-data","text_parsing-and-structuring-log-data_0","callout_parsing-and-structuring-log-data_0","title_centralizing-and-aggregating-logs","text_centralizing-and-aggregating-logs_0","figure_4","text_centralizing-and-aggregating-logs_0_cont_figure_4","callout_centralizing-and-aggregating-logs_0","title_storing-retaining-and-rotating-logs","text_storing-retaining-and-rotating-logs_0","callout_storing-retaining-and-rotating-logs_0","title_analyzing-and-correlating-logs","text_analyzing-and-correlating-logs_0","callout_analyzing-and-correlating-logs_0","title_log-management-vs-siem","text_log-management-vs-siem_0","figure_5","text_log-management-vs-siem_0_cont_figure_5","title_log-management-best-practices","text_log-management-best-practices_0","figure_6","text_log-management-best-practices_0_cont_figure_6","callout_log-management-best-practices_0","title_why-manage-logs-on-observe","text_why-manage-logs-on-observe_0","figure_7","text_why-manage-logs-on-observe_0_cont_figure_7","callout_why-manage-logs-on-observe_0"]},"flexible_column_content_container_2":{"additionalClasses":"hub-sidebar","layout":"SIMPLE","id":"hub-body-aside",":type":"snowflake-site/components/flexible-column-container/flexible-column-content-container","appliedCssClassNames":"snowflake-responsive-container-inner-padding-small",":items":{"container":{"additionalClasses":"sticky-sidebar","columnClassNames":{"text_943981956_copy_":"aem-GridColumn aem-GridColumn--default--12","text_copy":"aem-GridColumn aem-GridColumn--default--12"},"gridClassNames":"aem-Grid aem-Grid--12 aem-Grid--default--12","layout":"RESPONSIVE_GRID","columnCount":12,"id":"container-3c210d4645",":type":"snowflake-site/components/container","appliedCssClassNames":"snowflake-responsive-container-inner-padding-medium",":items":{"text_943981956_copy_":{"id":"text-69a1c8a2ac","additionalClasses":"eyebrow-text","text":"\u003Cp\u003EIn This Guide\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-size-regular"},"text_copy":{"id":"text-fa114f2dec","additionalClasses":"page-toc","text":"\u003Cul\u003E\u003Cli data-anchor=\"what-is-log-management\"\u003EWhat is log management?\u003C/li\u003E\u003Cli data-anchor=\"types-of-logs-and-log-data-formats\"\u003ETypes of logs and log data formats\u003C/li\u003E\u003Cli data-anchor=\"how-log-management-works-the-log-lifecycle\"\u003EHow log management works: the log lifecycle\u003C/li\u003E\u003Cli data-anchor=\"collecting-shipping-and-forwarding-logs\"\u003ECollecting, shipping and forwarding logs\u003C/li\u003E\u003Cli data-anchor=\"parsing-and-structuring-log-data\"\u003EParsing and structuring log data\u003C/li\u003E\u003Cli data-anchor=\"centralizing-and-aggregating-logs\"\u003ECentralizing and aggregating logs\u003C/li\u003E\u003Cli data-anchor=\"storing-retaining-and-rotating-logs\"\u003EStoring, retaining and rotating logs\u003C/li\u003E\u003Cli data-anchor=\"analyzing-and-correlating-logs\"\u003EAnalyzing and correlating logs\u003C/li\u003E\u003Cli data-anchor=\"log-management-vs-siem\"\u003ELog management vs. SIEM\u003C/li\u003E\u003Cli data-anchor=\"log-management-best-practices\"\u003ELog management best practices\u003C/li\u003E\u003Cli data-anchor=\"why-manage-logs-on-observe\"\u003EWhy manage logs on Observe\u003C/li\u003E\u003C/ul\u003E","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-size-small text-color-text-05"}},":itemsOrder":["text_943981956_copy_","text_copy"]}},":itemsOrder":["container"]},"isBlogPage":false,"isActiveTOC":false,":type":"snowflake-site/components/flexible-column-container"},"flexible_column_cont_1786318617":{"id":"flexible-column-container-935622d189","propertiesId":"hub-faq","type":"2-column-40-60","alignColumns":"top","containerMaxWidth":"extra-large","topPadding":"large","bottomPadding":"large","spaceBetween":"small","reverseOnMobile":false,"carouselOnMobile":false,"backgroundImageOption":"none","flexible_column_content_container_1":{"layout":"SIMPLE","id":"hub-faq-intro",":type":"snowflake-site/components/flexible-column-container/flexible-column-content-container","appliedCssClassNames":"snowflake-responsive-container-inner-padding-extra-small",":items":{"title_v2_copy":{"id":"title-v2-dd81dc02a4","additionalClasses":"hub-faq__headline","type":"heading2","lines":["Frequently Asked Questions"],":type":"snowflake-site/components/title-v2","appliedCssClassNames":"left-alignment"},"text_copy":{"id":"text-04f833047a","additionalClasses":"hub-faq__subheadline","text":"\u003Cp\u003EYour common questions about log management, answered by Snowflake experts.\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"}},":itemsOrder":["title_v2_copy","text_copy"]},"flexible_column_content_container_2":{"layout":"SIMPLE","id":"hub-faq-accordions",":type":"snowflake-site/components/flexible-column-container/flexible-column-content-container",":items":{"simple_snowflake_acc":{"id":"simple-snowflake-accordion-869f799094","additionalClasses":"seo-hub__faqs","showDivider":false,"accordionItemsList":[{"title":"What is the difference between log management and observability?","richText":"\u003Cp\u003ELog management focuses on collecting, storing and analyzing log data throughout its lifecycle. Observability is a broader practice that combines logs and metrics, along with traces, to help teams understand how distributed systems behave and identify the root cause of issues.\u003C/p\u003E"},{"title":"What is the difference between log management and a SIEM?","richText":"\u003Cp\u003ELog management provides the foundation for collecting and retaining operational logs. A SIEM builds on that data by applying security analytics and threat detection. This helps security teams identify suspicious activity and respond to potential incidents.\u003C/p\u003E"},{"title":"What is the difference between log management and log analytics?","richText":"\u003Cp\u003ELog management covers the complete lifecycle of log data, from collection through retention. Log analytics focuses on extracting insight from that data by searching, correlating and visualizing events to support troubleshooting and operational decision-making.\u003C/p\u003E"},{"title":"How long should you retain logs?","richText":"\u003Cp\u003EThere is no universal retention period. Organizations typically define retention based on operational requirements and compliance obligations. Frequently accessed logs often remain in hot storage and older data moves to lower-cost storage tiers for long-term preservation.\u003C/p\u003E"},{"title":"What are the stages of the log management process?","richText":"\u003Cp\u003EThe log management lifecycle begins with generating and collecting logs before they are transported, parsed, centralized, stored, analyzed and eventually retired. Each stage helps ensure log data remains accessible, reliable and cost-effective throughout its useful life.\u003C/p\u003E"}],":type":"snowflake-site/components/simple-snowflake-accordion"}},":itemsOrder":["simple_snowflake_acc"]},"isBlogPage":false,"isActiveTOC":false,":type":"snowflake-site/components/flexible-column-container","appliedCssClassNames":"snowflake-flexible-column-container-gray-10-bg"},"flexible_column_cont_1467213961":{"id":"flexible-column-container-e503849ec3","propertiesId":"hub-explore-resources-header","type":"1-column","alignColumns":"top","containerMaxWidth":"extra-large","topPadding":"large","bottomPadding":"none","spaceBetween":"small","reverseOnMobile":false,"carouselOnMobile":false,"backgroundImageOption":"none","flexible_column_content_container_1":{"layout":"SIMPLE","id":"container-2980f4ea99",":type":"snowflake-site/components/flexible-column-container/flexible-column-content-container",":items":{"title_v2":{"id":"title-v2-b2bb0c753a","additionalClasses":"hub-explore-resources-header__headline","type":"heading2","lines":["Explore Observability Resources"],":type":"snowflake-site/components/title-v2","appliedCssClassNames":"left-alignment"}},":itemsOrder":["title_v2"]},"isBlogPage":false,"isActiveTOC":false,":type":"snowflake-site/components/flexible-column-container","appliedCssClassNames":"snowflake-flexible-column-container-gray-10-bg"},"flexible_column_cont_912630531":{"id":"flexible-column-container-fa233ab769","propertiesId":"hub-explore-resources-grid","type":"1-column","alignColumns":"top","containerMaxWidth":"extra-large","topPadding":"small","bottomPadding":"large","spaceBetween":"small","reverseOnMobile":false,"carouselOnMobile":false,"backgroundImageOption":"none","flexible_column_content_container_1":{"layout":"SIMPLE","id":"hub-explore-resources-grid-inner",":type":"snowflake-site/components/flexible-column-container/flexible-column-content-container",":items":{"resource_chip_0":{"id":"content-chip-cc1b201f6a","tagText":"BLOG","tagColor":"#71D3DC","cta":{"id":"cta","showOutboundIcon":false,"buttonLink":{"valid":true,"url":"https://www.snowflake.com/en/blog/cto-circle-ai-native-engineering/#snowflake-blog-author-chip-title"},"linkTargetContentType":"GENERIC","linkType":"SNOWFLAKE_EXTERNAL",":type":"snowflake-site/components/button","text":"Read more"},"headline":{"id":"title-v2-118c9b3763","type":"heading5","lines":["Lessons from Engineering Leaders Building AI-Native Organizations"],":type":"snowflake-site/components/title-v2"},":type":"snowflake-site/components/content-chip","appliedCssClassNames":"snowflake-content-chip-white-bg"},"resource_chip_1":{"id":"content-chip-926d20085d","tagText":"CUSTOMER STORY","tagColor":"#71D3DC","cta":{"id":"cta","showOutboundIcon":false,"buttonLink":{"valid":true,"url":"https://www.observeinc.com/stories/progressive-leasing"},"linkTargetContentType":"GENERIC","linkType":"SNOWFLAKE_EXTERNAL",":type":"snowflake-site/components/button","text":"Read more"},"headline":{"id":"title-v2-6045b96714","type":"heading5","lines":["Progressive Leasing Accelerates Software Delivery with Observe AI SRE"],":type":"snowflake-site/components/title-v2"},":type":"snowflake-site/components/content-chip","appliedCssClassNames":"snowflake-content-chip-white-bg"},"resource_chip_2":{"id":"content-chip-c9d9dcffcb","tagText":"BLOG","tagColor":"#71D3DC","cta":{"id":"cta","showOutboundIcon":false,"buttonLink":{"valid":true,"url":"https://www.observeinc.com/stories/vivun"},"linkTargetContentType":"GENERIC","linkType":"SNOWFLAKE_EXTERNAL",":type":"snowflake-site/components/button","text":"Read more"},"headline":{"id":"title-v2-39f194015a","type":"heading5","lines":["Observe Becomes a Force Multiplier for Vivun"],":type":"snowflake-site/components/title-v2"},":type":"snowflake-site/components/content-chip","appliedCssClassNames":"snowflake-content-chip-white-bg"},"resource_chip_3":{"id":"content-chip-64d71be6d1","tagText":"CUSTOMER STORY","tagColor":"#71D3DC","cta":{"id":"cta","showOutboundIcon":false,"buttonLink":{"valid":true,"url":"https://www.observeinc.com/stories/dialpad"},"linkTargetContentType":"GENERIC","linkType":"SNOWFLAKE_EXTERNAL",":type":"snowflake-site/components/button","text":"Read more"},"headline":{"id":"title-v2-e0b6e5be2f","type":"heading5","lines":["Dialpad Expedites Mean Time to Resolution with Observe"],":type":"snowflake-site/components/title-v2"},":type":"snowflake-site/components/content-chip","appliedCssClassNames":"snowflake-content-chip-white-bg"}},":itemsOrder":["resource_chip_0","resource_chip_1","resource_chip_2","resource_chip_3"]},"isBlogPage":false,"isActiveTOC":false,":type":"snowflake-site/components/flexible-column-container","appliedCssClassNames":"snowflake-flexible-column-container-gray-10-bg"},"flexible_column_cont_1158003461":{"id":"flexible-column-container-d28ff6e5ce","propertiesId":"hub-explore-topics-header","type":"1-column","alignColumns":"top","containerMaxWidth":"extra-large","topPadding":"large","bottomPadding":"none","spaceBetween":"small","reverseOnMobile":false,"carouselOnMobile":false,"backgroundImageOption":"none","flexible_column_content_container_1":{"layout":"SIMPLE","id":"container-fccf7d2918",":type":"snowflake-site/components/flexible-column-container/flexible-column-content-container","appliedCssClassNames":"snowflake-responsive-container-inner-padding-extra-small",":items":{"title_v2_copy_copy":{"id":"title-v2-c6971ece38","additionalClasses":"hub-explore-topics-header__headline","type":"heading2","lines":["Explore Observability Topics"],":type":"snowflake-site/components/title-v2","appliedCssClassNames":"left-alignment"},"text_copy_copy":{"id":"text-8df0b7ea90","additionalClasses":"hub-explore-topics-header__subheadline","text":"\u003Cp\u003EDeep dives into every aspect of observability\u003C/p\u003E\r\n","richText":true,":type":"snowflake-site/components/text","appliedCssClassNames":"text-color-text-05"}},":itemsOrder":["title_v2_copy_copy","text_copy_copy"]},"isBlogPage":false,"isActiveTOC":false,":type":"snowflake-site/components/flexible-column-container","appliedCssClassNames":"snowflake-flexible-column-container-white-bg"},"flexible_column_cont_1377146023":{"id":"flexible-column-container-0ab811616d","propertiesId":"hub-explore-topics-grid","type":"3-column-even","alignColumns":"top","containerMaxWidth":"extra-large","topPadding":"small","bottomPadding":"large","spaceBetween":"small","reverseOnMobile":false,"carouselOnMobile":false,"backgroundImageOption":"none","flexible_column_content_container_1":{"layout":"SIMPLE","id":"container-6240383472",":type":"snowflake-site/components/flexible-column-container/flexible-column-content-container",":items":{"topic_card_0":{"id":"card-v2-1f4751cbb8","configurationStatus":{"configured":true,"message":""},"text":{"id":"text","text":"\u003Cp\u003EFoundational guide to enterprise AI: how it works, where it's headed and what it means for your business.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text"},"layoutStyle":"vertical",":type":"snowflake-site/components/card-v2","title":{"id":"title","type":"heading4","lines":["Artificial Intelligence"],":type":"snowflake-site/components/title-v2"},"button":{"id":"button","showOutboundIcon":false,"buttonLink":{"valid":true,"url":"/en/artificial-intelligence/"},"linkTargetContentType":"GENERIC","linkType":"SNOWFLAKE_INTERNAL",":type":"snowflake-site/components/button","text":"Learn more"},"type":"content-card"}},":itemsOrder":["topic_card_0"]},"flexible_column_content_container_2":{"layout":"SIMPLE","id":"container-9616e96674",":type":"snowflake-site/components/flexible-column-container/flexible-column-content-container",":items":{"topic_card_1":{"id":"card-v2-fb2b7c146c","configurationStatus":{"configured":true,"message":""},"text":{"id":"text","text":"\u003Cp\u003EFoundational guide to enterprise data governance: how it works, why it matters and what it means for your business.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text"},"layoutStyle":"vertical",":type":"snowflake-site/components/card-v2","title":{"id":"title","type":"heading4","lines":["Data Governance"],":type":"snowflake-site/components/title-v2"},"button":{"id":"button","showOutboundIcon":false,"buttonLink":{"valid":true,"url":"/en/data-governance/"},"linkTargetContentType":"GENERIC","linkType":"SNOWFLAKE_INTERNAL",":type":"snowflake-site/components/button","text":"Learn more"},"type":"content-card"}},":itemsOrder":["topic_card_1"]},"flexible_column_content_container_3":{"layout":"SIMPLE","id":"container-24cddbcb0f",":type":"snowflake-site/components/flexible-column-container/flexible-column-content-container",":items":{"topic_card_2":{"id":"card-v2-5f151d0fe4","configurationStatus":{"configured":true,"message":""},"text":{"id":"text","text":"\u003Cp\u003EPractical guide to tracing AI behavior, detecting drift and improving the quality, cost and control of production AI systems.\u003C/p\u003E","richText":true,":type":"snowflake-site/components/text"},"layoutStyle":"vertical",":type":"snowflake-site/components/card-v2","title":{"id":"title","type":"heading4","lines":["AI Observability"],":type":"snowflake-site/components/title-v2"},"button":{"id":"button","showOutboundIcon":false,"buttonLink":{"valid":true,"url":"/en/artificial-intelligence/observability/"},"linkTargetContentType":"GENERIC","linkType":"SNOWFLAKE_INTERNAL",":type":"snowflake-site/components/button","text":"Learn more"},"type":"content-card"}},":itemsOrder":["topic_card_2"]},"isBlogPage":false,"isActiveTOC":false,":type":"snowflake-site/components/flexible-column-container","appliedCssClassNames":"snowflake-flexible-column-container-white-bg"}},":itemsOrder":["flexible_column_cont","flexible_column_cont_939100716","flexible_column_cont_1398138236","flexible_column_cont_663228916","flexible_column_cont_1786318617","flexible_column_cont_1467213961","flexible_column_cont_912630531","flexible_column_cont_1158003461","flexible_column_cont_1377146023"],":type":"wcm/foundation/components/responsivegrid"},"modal_container":{"layout":"SIMPLE","id":"container-790ca3ced7",":type":"snowflake-site/components/modal/modal-container",":items":{},":itemsOrder":[]},"markup_editor_928258845":{"id":"markup-editor-4324f77565","title":" ","cssContent":".snowflake-flexible-column-container-gray-10-bg\u003E.snowflake-flexible-column-container{background-color:var(--ui-background-05) !important}.text-size-regular:has(.seo-hub-hero__related-topic-label){display:flex;align-items:center}.hub-hero__headline span{text-transform:none !important}.hub-hero__subheadline p{max-width:70ch;margin-top:8px}.hub-hero__authors \u003E .container \u003E .cmp-container \u003E .aem-container{display:flex;flex-direction:row}.hub-hero__authors \u003E .container \u003E .cmp-container \u003E .aem-container \u003E div{width:auto !important;margin:24px 48px 0 0 !important}.hub-hero__authors .heading-5-v2{gap:var(--spacing-00)}.hub-hero__authors .snowflake-content-chip-button{display:none !important}.hub-hero__authors .snowflake-person-chip-content .body-2,.hub-hero__authors .snowflake-content-chip-content .snowflake-title-v2-line{font-size:16px !important;line-height:20px !important;font-family:\"Lato\",sans-serif !important;color:#000 !important;font-weight:600 !important}.hub-hero__authors .snowflake-person-chip-content .body-3,.hub-hero__authors .snowflake-content-chip-content .snowflake-title-v2-line:not(:first-child){font-weight:400 !important;color:var(--text-05) !important;font-size:16px !important}.hub-hero__authors .snowflake-image-container img{aspect-ratio:1 !important;border-radius:100%;overflow:hidden}.hub-hero__authors .snowflake-person-chip-avatar{width:56px;height:56px}.hub-hero__authors .snowflake-content-chip{align-items:center;display:inline-flex}.hub-hero__authors .snowflake-content-chip-image{max-width:56px;line-height:0;margin-right:var(--spacing-03)}.hub-hero__authors .snowflake-person-chip-inner-horizontal{gap:var(--spacing-03)}@media screen and (min-width:1367px){.hub-hero__headline .heading-1-v2{font-size:48px;line-height:44px}}#hub-explore-resources-grid-inner\u003E.container\u003E.cmp-container\u003E.aem-container{display:flex;flex-direction:row;flex-wrap:wrap;gap:24px}#hub-explore-resources-grid-inner\u003E.container\u003E.cmp-container\u003E.aem-container::before,#hub-explore-resources-grid-inner\u003E.container\u003E.cmp-container\u003E.aem-container::after{display:none}#hub-explore-resources-grid-inner\u003E.container\u003E.cmp-container\u003E.aem-container\u003Ediv{width:calc(25% - 18px)}.text-color-text-05 .snowflake-text h2,.text-color-text-05.cq-Editable-dom h2,.text-color-text-05 .snowflake-text h3,.text-color-text-05.cq-Editable-dom h3,.text-color-text-05 .snowflake-text h4,.text-color-text-05.cq-Editable-dom h4,.text-color-text-05 .snowflake-text h5,.text-color-text-05.cq-Editable-dom h5,.text-color-text-05 .snowflake-text h6,.text-color-text-05.cq-Editable-dom h6{color:#000 !important}","isGSAPEnabled":false,":type":"snowflake-site/components/markup-editor"},"markup_editor_597730182":{"id":"markup-editor-8c188ecfb6","title":" ","cssContent":".sf-copy-markdown [data-copy-md]{display:inline-flex;align-items:center;gap:6px;padding:8px 16px;font-family:'Texta',sans-serif;text-transform:uppercase;font-weight:800 !important;font-size:14px;font-weight:500;color:#11567f;background:#f0faff;border:1px solid #b8e6f9;border-radius:24px;cursor:pointer;transition:background .2s ease,border-color .2s ease,color .2s ease}.sf-copy-markdown [data-copy-md]:hover{background:#ddf3fc;border-color:#29b5e8}.sf-copy-markdown [data-copy-md][data-copied=\"1\"]{color:#0f7b3e;background:#ecfdf5;border-color:#6ee7a0;pointer-events:none}.sf-copy-markdown [data-copy-md] svg{flex-shrink:0}.longform-conten .snowflake-content-chip-white-bg .snowflake-content-chip{box-shadow:0 0 24px 4px rgba(0,0,0,.02),0 4px 8px 0 rgba(0,0,0,.04);flex-direction:row-reverse;align-items:center}.longform-conten .snowflake-content-chip-button{display:none}.longform-conten .snowflake-content-chip-image__inner{aspect-ratio:5 / 3;display:flex;justify-content:center;align-items:center;background-color:var(--ui-01);border-radius:4px}.longform-conten .snowflake-content-chip-image{margin-right:0;margin-left:48px}.longform-conten .snowflake-content-chip-image img{width:50%;border-radius:0 !important;object-fit:contain}.longform-content .black-blue-text-color .snowflake-title-v2-line:not(:first-child){font-size:14px !important;font-weight:400 !important;color:rgba(0,0,0,.6) !important;margin-top:8px !important}.page-toc ul li:first-child{padding-top:0 !important}.page-toc ul li:last-child{padding-bottom:0 !important}.seo-hub__top-bar \u003E .container \u003E .cmp-container \u003E .aem-container \u003E div:first-child{flex-grow:1}.sf-copy-markdown{margin-top:40px !important}.page-toc ul{margin-top:16px !important}.seo-hub__top-bar \u003E .container \u003E .cmp-container \u003E .aem-container{display:flex;justify-content:space-between}.sf-copy-markdown{}.callout.snowflake-text p:not(:first-child){margin-top:var(--spacing-01)}.callout \u003E span \u003E p:first-child \u003E strong,.callout \u003E span \u003E p:first-child \u003E b{text-transform:uppercase;font-family:'Texta',sans-serif;font-size:16px !important;color:var(--ui-01) !important}.seo-hub-hero__subheadline p{max-width:50ch}.tag-group ul{list-style-type:none;padding:0;margin:0;display:flex;flex-direction:row;row-gap:12px;column-gap:8px;align-items:center;flex-wrap:wrap}.tag-group ul li:first-child{flex-shrink:0}.tag-group ul li a{display:inline-block;padding:2px 12px;border-radius:48px;background-color:#ededed;color:#666;font-size:14px !important}@media screen and (min-width:1367px){.seo-hub-hero__headline span.snowflake-title-v2-line{font-size:56px !important}}.callout.snowflake-text p:not(:first-child){margin-top:var(--spacing-01)}.callout \u003E span \u003E p:first-child \u003E b{text-transform:uppercase;font-family:'Texta',sans-serif;font-size:16px !important;color:var(--ui-01) !important}.seo-hub-hero__subheadline p{max-width:80ch}#hero:has(.snowflake-youtube-lite) .seo-hub-hero__subheadline p{max-width:50ch}.tag-group ul{list-style-type:none;padding:0;margin:0;display:flex;flex-direction:row;row-gap:12px;column-gap:8px;align-items:center;flex-wrap:wrap}.tag-group ul li:first-child{width:100%;flex-shrink:0}.tag-group ul li a{display:inline-block;padding:2px 12px;border-radius:48px;background-color:#ededed;color:#666;font-size:14px !important}@media screen and (min-width:1367px){.seo-hub-hero__headline span.snowflake-title-v2-line{font-size:56px !important}}","isGSAPEnabled":false,":type":"snowflake-site/components/markup-editor"},"markup_editor":{"id":"markup-editor-16abe92e5b","title":" ","cssContent":"div.snowflake-breadcrumb a.snowflake-breadcrumb-item,.snowflake-breadcrumb div.snowflake-breadcrumb-item{text-transform:none;font-weight:500}.snowflake-breadcrumb svg{display:none !important}.snowflake-breadcrumb a:has(svg)::after{content:'/';margin:0 12px;color:#666}.hub-sidebar{padding:0 40px}.sticky-sidebar{max-width:340px;margin-left:auto}.page-toc ul{list-style-type:none;padding:0}.page-toc li{padding:8px 16px;border-left:4px solid var(--ui-01);cursor:pointer;transition:300ms ease all}.page-toc li:hover{color:var(--ui-01);border-color:#7fd3f1;transition:300ms ease all}.callout,.customer-card{background-color:#eef9fd;border-left:4px solid var(--ui-01);padding:24px 24px 24px 32px;border-radius:4px}.logo-container{max-width:180px}.longform-content li{margin-top:1rem !important}div.longform-content p{max-width:80ch}.bolder .snowflake-title-v2-line{font-weight:900 !important}.border-top\u003Ediv{border-top:1px solid #ccc;padding-top:48px}.related-topics ul{list-style-type:none;padding:0;margin:0;display:flex;gap:8px;flex-wrap:wrap}.related-topics li{display:inline-block;border:1px solid #ccc;padding:4px 12px;border-radius:24px}div.longform-content .snowflake-text h2,div.longform-content .snowflake-text .heading-2-v2,div.longform-content .snowflake-text h3,div.longform-content .snowflake-text .heading-3-v2,div.longform-content .snowflake-title-v2 .heading-3-v2,div.longform-content .snowflake-text h4,div.longform-content .snowflake-text .heading-4-v2,div.longform-content .snowflake-title-v2 .heading-4-v2,div.longform-content .snowflake-text h5,div.longform-content .snowflake-text .heading-5-v2,div.longform-content .snowflake-title-v2 .heading-5-v2,div.longform-content .snowflake-text h6,div.longform-content .snowflake-title-v2 .heading-6-v2,div.longform-content .snowflake-text .heading-6-v2{text-transform:none !important}div.longform-content .snowflake-text h2,div.longform-content .snowflake-text .heading-2-v2,div.longform-content .snowflake-text h3,div.longform-content .snowflake-text .heading-3-v2,div.longform-content .snowflake-text h4,div.longform-content .snowflake-text .heading-4-v2,div.longform-content .snowflake-text h5,div.longform-content .snowflake-text .heading-5-v2,div.longform-content .snowflake-text h6,div.longform-content .snowflake-text .heading-6-v2{margin-top:1.5rem !important;line-height:1.1 !important}div.longform-content .snowflake-text h3,div.longform-content .snowflake-text .heading-3-v2,div.longform-content .snowflake-title-v2 .heading-3-v2,div.longform-content .snowflake-text h4,div.longform-content .snowflake-text .heading-4-v2,div.longform-content .snowflake-title-v2 .heading-4-v2,div.longform-content .snowflake-text h5,div.longform-content .snowflake-text .heading-5-v2,div.longform-content .snowflake-title-v2 .heading-5-v2,div.longform-content .snowflake-text h6,div.longform-content .snowflake-text .heading-6-v2,div.longform-content .snowflake-title-v2 .heading-6-v2{font-family:Lato,sans-serif !important;font-weight:800 !important}div.longform-content .snowflake-text h2,div.longform-content .snowflake-text .heading-2-v2,div.longform-content .snowflake-title-v2 .heading-2-v2{text-transform:none !important;font-size:28px !important}div.longform-content .snowflake-text h3,div.longform-content .snowflake-text .heading-3-v2,div.longform-content .snowflake-title-v2 .heading-3-v2{font-size:22px !important}div.longform-content .snowflake-text h4,div.longform-content .snowflake-text .heading-4-v2,div.longform-content .snowflake-title-v2 .heading-4-v2{font-size:18px !important}div.longform-content .snowflake-text h5,div.longform-content .snowflake-text .heading-5-v2,div.longform-content .snowflake-title-v2 .heading-5-v2{font-size:16px !important}div.longform-content .snowflake-text h6,div.longform-content .snowflake-text .heading-6-v2,div.longform-content .snowflake-title-v2 .heading-6-v2{font-size:14px !important}@media screen and (min-width:992px){div.longform-content .snowflake-text h2,div.longform-content .snowflake-text .heading-2-v2,div.longform-content .snowflake-title-v2 .heading-2-v2{font-size:38px !important}div.longform-content .snowflake-text h3,div.longform-content .snowflake-text .heading-3-v2,div.longform-content .snowflake-title-v2 .heading-3-v2{font-size:26px !important}div.longform-content .snowflake-text h4,div.longform-content .snowflake-text .heading-4-v2,div.longform-content .snowflake-title-v2 .heading-4-v2{font-size:22px !important}div.longform-content .snowflake-text h5,div.longform-content .snowflake-text .heading-5-v2,div.longform-content .snowflake-title-v2 .heading-5-v2{font-size:18px !important}div.longform-content .snowflake-text h6,div.longform-content .snowflake-text .heading-6-v2,div.longform-content .snowflake-title-v2 .heading-6-v2{font-size:16px !important}}.sticky-sidebar .page-toc li.is-active{font-weight:600;color:var(--snow-blue,#29b5e8)}.sticky-sidebar .page-toc li[data-anchor]{cursor:pointer}.longform-content table{margin-top:24px;margin-bottom:24px;width:100%;background-color:var(--ui-background-01);border-collapse:collapse;border:2px solid var(--ui-background-09);font-family:'Lato',sans-serif;color:var(--ui-background-09)}.longform-content table thead{background-color:var(--ui-01)}.longform-content th,.longform-content td{min-width:120px;border:2px solid var(--ui-background-09);padding:var(--spacing-01)}.longform-content ol{margin-top:0 !important}.longform-content ol li{margin-bottom:1rem !important}.longform-content ul li{margin:0;padding:0 0 0 32px;position:relative}.longform-content ul{list-style-type:none}.longform-content ul li::before{content:\"\";display:block;border-radius:100%;background:#29b5e8;width:18px;height:18px;position:absolute;top:4px;left:0;border:5px solid #e5f2f7;box-sizing:border-box}.seo-customer.snowflake-card-v2-advanced-horizontal .snowflake-card-v2-advanced-image-container{max-width:200px}.seo-customer.snowflake-card-v2-advanced-horizontal .snowflake-card-v2-advanced-image-container img{object-fit:contain}.related-topics-outer-container \u003E .container \u003E .cmp-container \u003E .aem-container{display:flex;flex-direction:row}.related-topics-outer-container \u003E .container \u003E .cmp-container \u003E .aem-container \u003E div{width:auto !important;margin:0 !important}.related-topics-outer-container \u003E .container \u003E .cmp-container \u003E .aem-container \u003E div:first-child{margin-right:16px !important;flex-shrink:0}","jsContent":"(function(){var OFFSET=100;if(window.gsap&&window.ScrollTrigger){gsap.registerPlugin(ScrollTrigger);var sidebar=document.querySelector('.sticky-sidebar');var body=document.querySelector('.longform-content');if(sidebar&&body){ScrollTrigger.create({trigger:sidebar,start:'top 100px',endTrigger:body,end:'bottom bottom',pin:sidebar,pinSpacing:false});}}document.addEventListener('click',function(e){var li=e.target.closest('li[data-anchor]');if(!li)return;var slug=li.getAttribute('data-anchor');var heading=document.querySelector('.anchor-title--'+CSS.escape(slug));if(!heading)return;e.preventDefault();var top=heading.getBoundingClientRect().top+window.pageYOffset-OFFSET;window.scrollTo({top:top,behavior:'smooth'});history.replaceState(null,'','#'+slug);},false);var headings=document.querySelectorAll('[class*=\"anchor-title--\"]');if(headings.length&&'IntersectionObserver'in window){var io=new IntersectionObserver(function(entries){entries.forEach(function(entry){if(!entry.isIntersecting)return;var cls=Array.from(entry.target.classList).find(function(c){return c.indexOf('anchor-title--')===0;});if(!cls)return;var slug=cls.replace('anchor-title--','');document.querySelectorAll('li[data-anchor]').forEach(function(li){li.classList.toggle('is-active',li.getAttribute('data-anchor')===slug);});});},{rootMargin:'-20% 0px -70% 0px',threshold:0});headings.forEach(function(h){io.observe(h);});}})();","isGSAPEnabled":true,":type":"snowflake-site/components/markup-editor"},"experiencefragment-footer":{"id":"experiencefragment-3a0df938ef","localizedFragmentVariationPath":"/content/experience-fragments/snowflake-site/language-masters/en/site/footer/master/jcr:content","configured":true,":type":"snowflake-site/components/experiencefragment","xfModelPath":"/content/experience-fragments/snowflake-site/language-masters/en/site/footer/master.xfmodel.json"},"experiencefragment":{"id":"experiencefragment-7d38b5a194","localizedFragmentVariationPath":"/content/experience-fragments/snowflake-site/language-masters/en/site/footer-legal-disclaimers/master/jcr:content","configured":true,":type":"snowflake-site/components/experiencefragment","xfModelPath":"/content/experience-fragments/snowflake-site/language-masters/en/site/footer-legal-disclaimers/master.xfmodel.json"}},":itemsOrder":["experiencefragment-banner","experiencefragment-header","responsivegrid","modal_container","markup_editor_928258845","markup_editor_597730182","markup_editor","experiencefragment-footer","experiencefragment"],":type":"wcm/foundation/components/responsivegrid"}},":itemsOrder":["root"],"locale":"en"}
  