Global Enterprise Cyber Defense Platform
Built in Thailand for security teams worldwide. Connect exposure, protection, detection, and response with zcr's 11-product enterprise cybersecurity platform.
What is Log Management?
Log Management is a system that collects, stores, and analyzes computer traffic data (log files) from devices such as firewalls, Microsoft Entra ID, and endpoint security (EDR) systems in one place — enabling audit and retrospective search in compliance with Thailand's Computer Crime Act B.E. 2560 (2017).
Which organizations are required to keep logs under Thailand's Computer Crime Act?
Every organization classified as a "service provider" must retain logs, including private companies, government agencies, universities, hotels, cafes offering Wi-Fi, ISPs, and hosting providers. Non-compliance can result in fines of up to ฿500,000.
How long do logs need to be retained?
Under Section 26 of the Computer Crime Act B.E. 2560, service providers must retain logs for at least 90 days, extendable up to 2 years in special cases if ordered by an authorized official.
How is zcrLog different from a SIEM?
zcrLog handles compliance log retention, while a SIEM runs SOC operations. zcrLog collects logs from firewalls, Windows, EDR and Microsoft Entra ID and retains them as Thailand's Computer Crime Act requires; it is certified to Thai standard มศอ. 4003.1-2560 whether deployed as SaaS, a dedicated VM or an appliance. SOC work such as incident SLA tracking and threat hunting runs on zcrSIEM, a separate product that ingests its own sources directly — zcrLog is not required.