Terminology Index
Glossary
2953 terms
Logs
Records of events generated by systems, applications, and devices, the raw material of monitoring, detection, and investigation. Collecting, centralizing, and analyzing logs is foundational to security visibility.
Logs are timestamped records of what systems and applications do, logons, connections, errors, transactions, that together form the evidence base for security. Defenders collect them centrally, search and correlate them for detection, and rely on them to investigate and reconstruct incidents. The completeness, quality, integrity, and retention of logs directly determine an organization's ability to see and respond to threats, making logs the bedrock of monitoring and telemetry.
Introduced in: Logging, Monitoring, and Telemetry
Examples
- Collecting system and application logs centrally for analysis.
- Searching logs to investigate what happened during an incident.
- Correlating logs across sources to detect an attack.
