Log Management and SIEM: The 180-Day CERT-In Requirement Most Enterprises Are Violating

By Deepika Nair · 2 June 2026

What CERT-In Actually Mandates on Logging

CERT-In Directions 2022 (Direction 6) explicitly states that all service providers, intermediaries, data centres, and government organisations must maintain "logs of all their ICT systems for a rolling period of 180 days" and that these logs must be maintained "within the Indian jurisdiction." Critically, NTP synchronisation is also mandated — all system clocks must be set to the Indian Standard Time (IST) zone, synchronised with the National Physical Laboratory (NPL) time server or a replica, ensuring accurate timestamps across all log sources. ISO/IEC 27001:2022 Annex A.8.15 requires logging of activities, exceptions, and events that can assist in future investigations. The RBI Cybersecurity Framework requires real-time log monitoring for BFSI organisations.

What Must Be Logged — CERT-In Mandatory Sources

Log SourceWhat to LogMinimum Retention
Firewalls / NGFWsAll allowed + denied connections, IPS alerts180 days
Active Directory / IAMLogon/logoff, failed auth, privilege changes, account creation/deletion180 days
Servers (OS)System events, service starts/stops, privilege use, file access (critical paths)180 days
DNS ServersAll query logs (source IP, queried domain, response)180 days
Web / Email GatewaysURL access logs, email routing, malware detections, DLP events180 days
Applications (critical)User activity, transactions, API calls, errors180 days

SIEM Architecture for Indian Enterprises

A Security Information and Event Management (SIEM) platform collects logs from all sources, normalises them into a common format, correlates events across sources to detect multi-stage attacks, and provides alerting, dashboards, and reporting for both operational and compliance use. For Indian mid-market enterprises, the practical SIEM options include: Elastic SIEM (open source, powerful, requires expertise), Wazuh (open source, CERT-In use-case community), Microsoft Sentinel (cloud-native, strong AD integration, data residency options), and commercial options like IBM QRadar or Splunk. For CERT-In data residency compliance, choose a SIEM that stores log data within Indian data centre regions.

NTP Synchronisation — The Overlooked CERT-In Requirement

CERT-In mandates that all ICT systems synchronise their clocks with the NPL Stratum-1 NTP server at time.nplindia.org or equivalent stratum-2 servers. Misconfigured system clocks make log correlation forensically useless — events appear out of sequence or with wrong timestamps. Configure all servers, network devices, and endpoints to synchronise NTP via a hierarchy that traces back to the NPL source. Verify NTP configuration as part of every server hardening check.

Log Management Assessed On-Site by InfraVeritas 360

Every IGaaS engagement assesses log coverage, SIEM architecture, retention configuration, and NTP synchronisation — producing a CERT-In compliance gap report with specific remediation actions.

Assess Your Log Management →