Log analysis examines system logs to detect anomalies and security events. Every login, every process start, every network connection generates log entries. Buried in that noise are the clues to an attack. A login from an unusual location. A service account running a PowerShell script at 3 a.m. A sudden spike in outbound traffic. Log analysis finds those patterns.
The challenge is volume. A mid-sized organization generates millions of log entries per day. Manual review is impossible. Security information and event management platforms collect, normalize, and correlate logs from many sources. They apply rules and machine learning to surface the events that matter. But even SIEMs generate false positives. The analyst still has to triage. Good log analysis starts with good logging. If the system does not log the event, no tool can analyze it. Many breaches go undetected because logging was disabled or incomplete. Audit policies need to be configured deliberately. Authentication events, process creation, and network connections are the minimum. Retention matters too. Attackers may dwell for months. Logs that roll off after 30 days leave gaps. The investigation needs history.
Log sources to prioritize
- Authentication — logins, failures, privilege changes
- Endpoint — process creation, file changes, service installs
- Network — firewall, DNS, proxy, and VPN logs
- Cloud — API calls, storage access, identity events
- Application — errors, admin actions, data exports
Logs are evidence. If they are not collected, the incident cannot be reconstructed.
Comments
No comments yet. Be the first to share a thought.
Leave a comment