How long do you keep logs from your servers / applications?
We currently store logs for 1 year (chose by convenience AFAICR), except from authentication events that we destroy after 6 months (maximum duration allowed by french CNIL for an employer to access authentication information from his employees).
What retention duration have you setup and why?
References to regulations are welcome, but I guess all use-cases are good to learn from 😉