Transaction logs are an important part of maintaining a secure and trustworthy system. They provide a record of system activities that can be reviewed during future audits, particularly when investigating or resolving disputes involving ADSS Server.


The Logs Archiving feature helps manage database storage and performance by periodically moving older transaction log records out of the database. This housekeeping process reduces database growth and helps maintain efficient database performance.


By default, log archiving is configured to:

  • Auto-archive every: 30 days Name
  • Archive records older than: 90 days


Each transaction record may consume several kilobytes of database storage. For systems with a low transaction volume, you can increase the retention period to 120 or 180 days, depending on your storage and audit requirements.


The Logs Archiving feature allows administrators to:

  • Enable or disable automatic archiving.
  • Configure the archiving schedule and retention period.
  • Manually archive TSL Monitor transaction logs.
  • Specify the location where archived logs are stored.
  • Optionally delete archived records from the database to reduce database size.


When automatic archiving is enabled, eligible transaction logs are periodically moved from the database to a ZIP file containing CSV data. You can also manually archive the logs by clicking Archive All Records.


Archived logs can later be imported back into ADSS Server for auditing and review. For information about importing archived logs, see TSL Logs.


Important: Log archiving is a resource-intensive operation and may affect system performance while it is running. Schedule automatic archiving during off-peak hours, when the system is experiencing low user activity. Alternatively, consider deploying a dedicated, load-balanced ADSS Server instance for housekeeping tasks by deploying the ADSS Server Core and Service instances on separate machines.


The integrity of archived logs can also be protected by digitally signing the archived log file using a Log Signing Key. This can be configured under Global Settings > System Certificates.


Logs Archiving Configuration

The following image shows the Logs Archiving configuration screen:



The following table describes the available configuration items:


Items

Description

Archived File Path

Specifies the location where archived transaction logs are stored as ZIP files containing CSV data.

Delete Records from Database Once Archived

Deletes transaction log records from the database after they have been successfully archived. If this option is not enabled, the archived records remain in the database. In this case, archiving provides a backup copy of the records but does not reduce database size. Enable this option carefully based on your retention, audit, and storage requirements.

Enable Auto-Archiving

Enables automatic archiving of eligible transaction logs according to the configured schedule.

Auto-Archive Every

Specifies how frequently, in days, the transaction logs should be archived.

Archive Records Older Than

Specifies the age, in days, after which transaction logs become eligible for automatic archiving.

Archive At

Specifies the time of day when automatic archiving is performed. Configure this time during off-peak hours to minimise the impact on system performance.

Archive All Records

Immediately archives all available TSL Monitor transaction logs to the configured Archived File Path.


After configuring the required settings, click Save to apply the changes.


Important: Do not open archived log files in Microsoft Excel. Excel may modify the file by adding or changing characters, which can corrupt the archived log data and prevent its integrity from being verified when the file is later re-imported into ADSS Server. If you need to inspect an archived file directly, use a text editor such as Notepad. For proper viewing and analysis, import the archived log file back into ADSS Server through the TSL Logs screen.


For more information about TSL log archiving, see the TSL Archiving documentation under ADSS Trust Manager. Note that each Trust Anchor has its own TSL archiving policy, which is configured in Trust Manager.

See also

Service Manager
HA Configuration
TSL Details

TSL Monitoring
TSL Logs
Logs Archiving
Alerts