---
name: cloud-logs-shared-responsibilities
title: Understanding your responsibilities when using IBM Cloud Logs
description: Learn about the management responsibilities and terms and conditions that you have when you use IBM Cloud Logs. For a high-level view of the service types in IBM Cloud and the breakdown of responsibilities between the customer and IBM for each type, see Shared responsibilities for IBM Cloud offerings.
last-updated: 2025-09-25
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/cloud-logs?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Understanding your responsibilities when using IBM Cloud Logs
{: #shared-responsibilities}

Learn about the management responsibilities and terms and conditions that you have when you use IBM Cloud Logs. For a high-level view of the service types in IBM Cloud and the breakdown of responsibilities between the customer and IBM for each type, see [Shared responsibilities for IBM Cloud offerings](https://cloud.ibm.com/docs/overview?topic=overview-shared-responsibilities&format=markdown).
{: shortdesc}

Review the following sections for the specific responsibilities for you and for IBM when you use IBM Cloud Logs. For the overall terms of use, see [IBM Cloud Terms and Notices](https://cloud.ibm.com/docs/overview?topic=overview-terms&format=markdown).


## Configuration
{: #sr-configuration}

| Task              | IBM Responsibilities | Your Responsibilities |
|-------------------|-------------------------------------------------|-----------------------|
| [Configuration of an IBM Cloud Logs data bucket](https://cloud.ibm.com/docs/cloud-logs?topic=cloud-logs-configure-data-bucket&format=markdown) | None | [TCO policies](https://cloud.ibm.com/docs/cloud-logs?topic=cloud-logs-tco-optimizer&format=markdown) sending data to the Analyze and alert and Store and search pipelines require a data bucket to be configured. If a data bucket is not configured for these policy types, there is a potential for data to be dropped.  \n  \n Without a data bucket, data will not be retained beyond the selected [service plan](https://cloud.ibm.com/docs/cloud-logs?topic=cloud-logs-service_plans&format=markdown).|
| Configuration of the Logging agent | Provides the ability to configure the Logging agent. | [Configure the Logging agent for your environment to meet your needs.](https://cloud.ibm.com/docs/cloud-logs?group=sending-data-to-a-cloud-logs-instance&format=markdown)  \n  \n Prior to configuring the Logging agent, review  [Considerations when you configure the Logging agent](https://cloud.ibm.com/docs/cloud-logs?topic=cloud-logs-agent-configuration-considerations&format=markdown) to understand how the Logging agent configuration affects processing of log data. |
{: caption="Responsibilities for service configuration" caption-side="top"}



## Incident and operations management
{: #incident-and-ops}

| Task              | IBM Responsibilities | Your Responsibilities |
|-------------------|-------------------------------------------------|-----------------------|
| Incident and operations management | Maintain service instances and infrastructure workloads. | Maintain incident and operations management of your data. |
| Monitor incidents  | Provide notifications for planned maintenance, security bulletins, or unplanned outages. | * Set preferences to [receive emails about platform notifications](https://cloud.ibm.com/docs/account?topic=account-email-prefs&format=markdown#setting-platform-notifications).  \n * Monitor the [IBM Cloud status page](https://cloud.ibm.com/status?selected=announcement) for general announcements. |
| Maintain IBM Cloud high availability SLA for IBM Cloud Logs   | * Provide IBM Cloud Logs functionality across availability zones in a Multi-Zone Region (MZR).  \n * Provide replication, fail-over features, and infrastructure maintenance and updates. | * Back up your IBM Cloud Logs configuration. For example, keep the configuration in a version control system so that you can reconfigure a region if needed.   \n * Comply with [Operational responsibilities when using IBM Cloud Object Storage](https://cloud.ibm.com/docs/cloud-object-storage?topic=cloud-object-storage-responsibilities&format=markdown).  \n * Comply with [Operational responsibilities when using IBM Cloud Event Notifications](https://cloud.ibm.com/docs/event-notifications?topic=event-notifications-en-responsibilities&format=markdown). |
{: caption="Responsibilities for incident and operations" caption-side="top"}


## Change management
{: #change-management}

| Task                                                    | IBM Responsibilities | Your Responsibilities |
|---------------------------------------------------------|-----------------------|--------|
| Updates to IBM Cloud Logs | * Provide major, minor, and patch version updates for IBM Cloud Logs interfaces.  \n * Document changes in the [IBM Cloud Support Center](https://cloud.ibm.com/unifiedsupport/supportcenter){: external} | Apply changes to keep up to the latest versions and functionality. |
{: caption="Responsibilities for change management" caption-side="top"}



## Identity and access management
{: #iam-responsibilities}


| Task                           | IBM Responsibilities | Your Responsibilities |
|--------------------------------|-------------------------------------------------|-----------------------|
| Manage permissions for IBM Cloud Logs. | Provide the ability to restrict access to resources.  \n  \n IBM is responsible for the security and compliance of the IBM Cloud Logs service. | * Restrict access to IBM Cloud Logs, IBM Cloud Object Storage and IBM Cloud Event Notifications resources by defining Cloud IAM access policies and authorizations.  \n * Define IAM policies to control data access.  \n * [Learn more about controlling access through IAM](https://cloud.ibm.com/docs/cloud-logs?topic=cloud-logs-iam&format=markdown).|
| Create service to service authorizations to grant authorizations between services. |  Provide the ability to restrict access to resources.  \n  \n IBM is responsible for the security and compliance of the IBM Cloud Logs service. | You must configure service to service authorizations so dependant services can communicate with one another. For more information see [Managing authorizations to grant access between services](https://cloud.ibm.com/docs/cloud-logs?topic=cloud-logs-iam-service-auth&format=markdown). |
| Use Service ID API keys or Trusted Profiles in production environments | None | While IBM Cloud Logs allows the use of individual user API keys, production environments should be configured using [Service ID API keys](https://cloud.ibm.com/docs/cloud-logs?topic=cloud-logs-iam-ingestion-serviceid-api-key&format=markdown) or [Trusted Profiles](https://cloud.ibm.com/docs/cloud-logs?topic=cloud-logs-iam-ingestion-trusted-profile&format=markdown).  \n  \n If individual user API keys are used, the authorization granted by those keys will be removed if the user creating those API keys is no longer an authorized IBM Cloud user.  \n  \n Individual user API keys should only be used in non-production environments. |
{: caption="Responsibilities for identity and access management" caption-side="top"}



## Security and regulation compliance
{: #security-compliance}


| Task                                       | IBM Responsibilities | Your Responsibilities |
|--------------------------------------------|-------------------------------------------------|-----------------------|
| Meet security and compliance objectives  | Maintain controls that are commensurate to various industry compliance standards.  | * Set up and maintain security and regulation compliance for your apps and data.  \n * When using IBM Cloud Object Storage, ensure you comply with [Data security](https://cloud.ibm.com/docs/cloud-object-storage?topic=cloud-object-storage-security&format=markdown) and [Compliance](https://cloud.ibm.com/docs/cloud-object-storage?topic=cloud-object-storage-compliance&format=markdown).  \n * When using IBM Cloud Event Notifications, ensure you comply with [Data security and compliance](https://cloud.ibm.com/docs/event-notifications?topic=event-notifications-en-data-security-and-compliance&format=markdown).  |
{: caption="Responsibilities for security and regulation compliance" caption-side="top"}


## Disaster recovery
{: #disaster-recovery}

Disaster recovery includes tasks such as:

* Providing dependencies on disaster recovery sites.
* Provisioning disaster recovery environments.
* Backing up data and configuration information.
* Replicating data and configuration information to the disaster recovery environment.
* Failover on disaster events.

| Task                                                            | IBM Responsibilities | Your Responsibilities |
|-----------------------------------------------------------------|-------------------------------------------------|-----------------------|
| Restore functionality for IBM Cloud Logs  | Recover and restart IBM Cloud Logs components after any disaster event. `[*]` |  [Complete the disaster recovery (DR) steps for IBM Cloud Logs](https://cloud.ibm.com/docs/cloud-logs?topic=cloud-logs-cloud-logs-ha-dr&format=markdown). |
| Backup IBM Cloud Logs components   | Ensure that backup of IBM Cloud Logs metadata is in place and properly working according to defined policies. | * Follow the IBM Cloud Object Storage disaster revovery strategy guidance. For more information, see [Data security](https://cloud.ibm.com/docs/cloud-object-storage?topic=cloud-object-storage-security&format=markdown), [Create a Secure Content Store](https://cloud.ibm.com/docs/cloud-object-storage?topic=cloud-object-storage-secure-content-store&format=markdown), and [Using replication for business continuity and disaster recovery](https://cloud.ibm.com/docs/cloud-object-storage?topic=cloud-object-storage-replication-overview&format=markdown#replication-bcdr).  \n * Ensure that log files in the IBM Cloud Object Storage bucket are retained according to the desired policy.  \n * Follow the IBM Cloud Event Notifications service disaster revovery strategy guidance. For more information, see [Securing your data in IBM Cloud Event Notifications](https://cloud.ibm.com/docs/event-notifications?topic=event-notifications-en-mng-data&format=markdown) and [Disaster recovery](https://cloud.ibm.com/docs/event-notifications?topic=event-notifications-en-responsibilities&format=markdown#en-disaster-recovery).|
{: caption="Responsibilities for disaster recovery" caption-side="top"}


`[*]` Recovered and restarted service components will not have customer's configurations or data reloaded.
{: note}