Firewall Log Management · Panel › Archive

Archive: signed, timestamped, and on a separate disk.

Every record in Live Logs is written at the same time to a separate disk as compressed archive files (segments). The Archive page lets you verify the integrity of these segments, download them, export them with a signature, and restore them to live when needed.

  • A SHA-256 chain per tenant
  • Ed25519 signature + a daily qualified timestamp (Kamu SM, Merkle root)
  • Verify · Download · Export · Restore to Live
Location
Panel › Archive
Segment format
Compressed archive files
Integrity
SHA-256 chain + Ed25519
Timestamp
Kamu SM, once a day
Export
≤500 segments / ≤4 GB, synchronous
Disk
Separate physical disk from live
izgate Archive page: archive size, segment, archived events and disk cards, scope/timestamp/signature/retention information, per-device archive summary and daily archive table
Archive: cards, per-device summary, the daily archive table and the restore jobs panel
What's on screen?

Top to bottom, what you'll see in the panel

  1. Title and top buttons: the "Archive" heading, an "Export" button and a refresh button.
  2. Top cards: Archive Size, Segment count, Archived Events count, and the Archive Disk (separate-disk label + fullness percentage + free space).
  3. Info cards: Scope (the archive's start-end date), Timestamp (the daily Kamu SM timestamp, with the number of timestamped/pending segments), Signature Public Key (a copyable fingerprint), and Retention (the archive retention period in days).
  4. Per-device archive card: for each device — segment count, size, event count, date range, and the verified/total segment ratio (e.g. "188/188").
  5. Daily Archive table: segments listed by day with device, type and date-range filters; each row shows the day, device, that day's log types (System/Traffic/VPN/Identity), segment count and event count; verify/download/export icons sit at the end of each row.
  6. Restore Jobs panel: requests to restore to live are listed here; if there are none, an empty state reads "No restore jobs."
What can you do?

Four operations, segment by segment

Verify

File, signature, key, chain and TSA are all verified with one click, proving the segment hasn't changed since it was created.

Download

The segment and manifest files can be downloaded separately.

Export

The selected date range is exported as a signed package (≤500 segments / ≤4 GB, synchronous) containing a README, a catalog, segments, a manifest and the TSA document.

Restore to live

Selected segments become temporarily searchable again and appear flagged in Live Logs; they stay live for the duration you choose, then drop back out.

Integrity and retention

Every segment links to the last, and every hour gets signed

The per-tenant segment chain proves the integrity of the whole archive, not just a single record.

SHA-256 chain

Every segment carries the previous segment's digest; deleting or altering a segment in between breaks the chain and verification fails.

Ed25519 signature

Each segment is signed with a key specific to your installation; the signature proves the file hasn't changed since it was produced.

Daily qualified timestamp

The digests of that day's not-yet-timestamped segments are combined into a Merkle root and independently timestamped once a day by the Public Certification Authority (Kamu SM), via İzHost's central service.

Live (the column-based ClickHouse database, for the duration you choose) and archive (file system) retention periods are set in parallel and independently under Settings > Disk Management; every log is written to both at the same time, and the overall retention period is whichever of the two is longer. Archive pruning cannot be undone and only removes segments older than your chosen cutoff date that fall entirely outside the retained scope.

How to use it?

Responding to a request with signed proof

1

Filter by device/date range

Pick the device, log type and date range you need in the Daily Archive table.

2

Verify the segment

Use the Verify icon to confirm file, signature, chain and TSA integrity with one click.

3

Download, export or restore it

Depending on your need, download the segment, export it in a signed package, or restore it temporarily to live and search it in Live Logs.

What to know

Limits and context

Export runs synchronously and is capped at ≤500 segments / ≤4 GB; larger ranges need more than one export. Restoring to live is temporary: the segment stays live for the duration you choose, then drops back out once it expires, with the signed copy in the archive unaffected. In an on-premises installation, actual disk paths and fullness are shown; there's no disk expansion from the panel (that's done manually on the host). In the cloud, your total quota is split into live/archive under Settings > Disk Management.

Related features

Continue from Archive

Live Logs

The screen where segments restored from the archive become searchable.

Disk Management

Quota, usage and retention settings for the live and archive disks.

Reports

17 ready-made reports across 8 categories; PDF, Excel and CSV output, scheduled jobs and templates.

Frequently asked questions

About Archive

Is the archive kept on the same disk as live logs?

No. Separate disks are required for /log (live) and /archive; in an on-premises installation, install.sh stops the installation if a separate disk isn't present.

How do I prove a segment hasn't been altered?

The Verify action checks the file's SHA-256 digest, its Ed25519 signature, its link to the previous segment in the chain, and the daily qualified timestamp (Kamu SM) together. If all four check out, the segment hasn't changed since it was produced.

What's in the export file?

You get a signed tar package containing a README, a catalog, the segment files, a manifest and the timestamp document obtained from Kamu SM; the operation is synchronous and capped at ≤500 segments / ≤4 GB.

Does a record restored to live become permanent?

No, it's temporary. The segment stays searchable in Live Logs for the duration you choose, then drops out of live once that period ends; the signed original copy in the archive is unaffected.

Can archive pruning be undone?

No. Archive pruning cannot be undone, and it only removes segments older than the chosen cutoff date that fall entirely outside the retained scope.

See all questions

Making your network Law No. 5651 compliant is a one-day job.

Configure izgate Cloud based on your number of firewall devices and storage needs; no setup, get started in minutes. Call us with any questions.