Verify
File, signature, key, chain and TSA are all verified with one click, proving the segment hasn't changed since it was created.
Every record in Live Logs is written at the same time to a separate disk as compressed archive files (segments). The Archive page lets you verify the integrity of these segments, download them, export them with a signature, and restore them to live when needed.
File, signature, key, chain and TSA are all verified with one click, proving the segment hasn't changed since it was created.
The segment and manifest files can be downloaded separately.
The selected date range is exported as a signed package (≤500 segments / ≤4 GB, synchronous) containing a README, a catalog, segments, a manifest and the TSA document.
Selected segments become temporarily searchable again and appear flagged in Live Logs; they stay live for the duration you choose, then drop back out.
The per-tenant segment chain proves the integrity of the whole archive, not just a single record.
Every segment carries the previous segment's digest; deleting or altering a segment in between breaks the chain and verification fails.
Each segment is signed with a key specific to your installation; the signature proves the file hasn't changed since it was produced.
The digests of that day's not-yet-timestamped segments are combined into a Merkle root and independently timestamped once a day by the Public Certification Authority (Kamu SM), via İzHost's central service.
Live (the column-based ClickHouse database, for the duration you choose) and archive (file system) retention periods are set in parallel and independently under Settings > Disk Management; every log is written to both at the same time, and the overall retention period is whichever of the two is longer. Archive pruning cannot be undone and only removes segments older than your chosen cutoff date that fall entirely outside the retained scope.
Pick the device, log type and date range you need in the Daily Archive table.
Use the Verify icon to confirm file, signature, chain and TSA integrity with one click.
Depending on your need, download the segment, export it in a signed package, or restore it temporarily to live and search it in Live Logs.
Export runs synchronously and is capped at ≤500 segments / ≤4 GB; larger ranges need more than one export. Restoring to live is temporary: the segment stays live for the duration you choose, then drops back out once it expires, with the signed copy in the archive unaffected. In an on-premises installation, actual disk paths and fullness are shown; there's no disk expansion from the panel (that's done manually on the host). In the cloud, your total quota is split into live/archive under Settings > Disk Management.
The screen where segments restored from the archive become searchable.
Quota, usage and retention settings for the live and archive disks.
17 ready-made reports across 8 categories; PDF, Excel and CSV output, scheduled jobs and templates.
No. Separate disks are required for /log (live) and /archive; in an on-premises installation, install.sh stops the installation if a separate disk isn't present.
The Verify action checks the file's SHA-256 digest, its Ed25519 signature, its link to the previous segment in the chain, and the daily qualified timestamp (Kamu SM) together. If all four check out, the segment hasn't changed since it was produced.
You get a signed tar package containing a README, a catalog, the segment files, a manifest and the timestamp document obtained from Kamu SM; the operation is synchronous and capped at ≤500 segments / ≤4 GB.
No, it's temporary. The segment stays searchable in Live Logs for the duration you choose, then drops out of live once that period ends; the signed original copy in the archive is unaffected.
No. Archive pruning cannot be undone, and it only removes segments older than the chosen cutoff date that fall entirely outside the retained scope.
Configure izgate Cloud based on your number of firewall devices and storage needs; no setup, get started in minutes. Call us with any questions.