QueryShield

What logs do I need to capture for LLM SQL forensics?

For an actionable forensic trail (SOC 2, HIPAA, PCI, and "what just happened" debugging):

Ship to your SIEM (Datadog, Splunk, Elastic, Chronicle). For HIPAA, retain six years; PCI DSS, one year online + three archived; SOC 2 typically one year.