MD4 Overview of logs: The importance of logs Flashcards
Logs
A log is a record of events that occur within an organization’s systems.
Logs contain multiple entries which detail information about a specific event or occurrence.
Log details
Include details like date, time, location, the action made, and the names of the users or systems who performed the action.
Log analysis
Log analysis is the process of examining logs to identify events of interest.
It’s helpful to be selective in what we log, so that we can log efficiently.
SIEM tools
SIEM tools provide security professionals with a high-level overview of what happens in a network. SIEM tools do this by first collecting data from multiple data sources. Then, the data gets aggregated or centralized in one place. Finally, the diverse log formats get normalized or converted into a single preferred format.
how do logs get collected?
Software known as log forwarders collect logs from various sources and automatically forward them to a centralized log repository for storage.
log types
Network
System
Application
Security logs
Authentication logs