Terminology Index

Glossary

2953 terms

Open concept maps
L
31

Logs

Records of events generated by systems, applications, and devices, the raw material of monitoring, detection, and investigation. Collecting, centralizing, and analyzing logs is foundational to security visibility.

Logs are timestamped records of what systems and applications do, logons, connections, errors, transactions, that together form the evidence base for security. Defenders collect them centrally, search and correlate them for detection, and rely on them to investigate and reconstruct incidents. The completeness, quality, integrity, and retention of logs directly determine an organization's ability to see and respond to threats, making logs the bedrock of monitoring and telemetry.

Introduced in: Logging, Monitoring, and Telemetry

Examples

  • Collecting system and application logs centrally for analysis.
  • Searching logs to investigate what happened during an incident.
  • Correlating logs across sources to detect an attack.
M
1