Terminology Index
Glossary
2953 terms
Log Source Taxonomy
A structured classification of the log sources available in an environment, organizing them by type, system, and the visibility they provide, so analysts know what data exists and which source answers a given question.
A log source taxonomy catalogs and categorizes the telemetry an organization collects, endpoint, network, identity, cloud, application logs and their specifics, so analysts and detection engineers know what is available and which source to query for a given need. It improves query writing, detection coverage planning, and gap identification, turning a sprawl of logs into an organized map. It is foundational to working efficiently in a SIEM and to reasoning about visibility.
Introduced in: SIEM Query Fundamentals
Examples
- Cataloging available logs by endpoint, network, identity, and cloud.
- Knowing which log source answers a given investigative question.
- Using the taxonomy to spot missing source categories.
Related
