Module 3 Flashcards
Log
A record of events that occur within an organization’s systems and networks
Common Log Sources
Firewall logs
Network logs
Server logs
Firewall Log
A record of attempted or established connections for incoming traffic from the Internet. Also includes outbound requests to the Internet from within the network.
Network Log
A record of all computers and devices that enter and leave the network. It also records connections between devices and services on the network.
Server Log
A record of events related to services, such as websites, emails, or file shares. It includes action, such as login, password, and username request.
Security Information and Event Management (SIEM)
An application that collects an analyzes log data to monitor critical activities in an organization
Metrics
Key technical attributes, such as response time, availability, and failure rate, which are used to assess the performance of a software application
Different Types of SIEM Tools
Self-hosted
Cloud-hosted
Hybrid
Splunk Enterprise
A self-hosted tool used to retain, analyze, and search an organizations log data to provide security information and alerts in real-time
Splunk Cloud
A cloud-hosted tool used to collect, search, and monitor log data
Chronicle
A cloud-native tool designed to retain, analyze, and search data