The audit log retention cap is 180 days and as far as I can tell there's no way to extend it. For anyone who needs to answer questions further back than that (compliance evidence, "who had access to this project last quarter", proving a permission change happened), what are you actually doing?
A few approaches I'm aware of, none of them great:
- Polling `/rest/api/3/auditing/record` on a schedule and dumping it somewhere yourself
- Exporting to a SIEM, though the export is capped at 10,000 activities
- A backup app, which covers restore but not really "who did what when"
- Accepting the 180 days and telling auditors that's the limit
Curious which of these people have landed on, and whether anyone has found something that handles permission and group membership changes specifically. Those only seem to exist in the audit log, so once the 180 days rolls off there's nothing left.
Also interested in whether this comes up for people in practice, or whether 180 days is fine for most teams.