Logging
Logging: The recording of security-relevant events so activity can be monitored, investigated, and audited. Effectiveness depends on reliable data, defined ownership, measurable criteria, and regular tuning.
How it works and where it fits
Logging connects data sources to detection or assessment logic. Raw records become security-relevant only when timing, identity, system context, and expected behavior are considered. Rules, correlations, statistical models, and analyst decisions may work together; no single method reliably covers every attack pattern.
Practical security relevance
Operational quality is reflected in coverage, data completeness, detection time, and false-alert workload. Data sources need owners, time synchronization, retention, and quality controls. Detections should be tested, versioned, and improved using real incidents. Every meaningful alert also requires triage guidance, escalation, and possible response actions.
Related concepts
- Log ManagementLog ManagementCollects, normalizes, stores, and manages event logs.: Collects, normalizes, stores, and manages event logs.
- MonitoringMonitoringThe continuous observation of systems, identities, networks, and controls for relevant changes.: The continuous observation of systems, identities, networks, and controls for relevant changes.
- Security Information and Event ManagementSecurity Information and Event ManagementCollects and correlates security events for monitoring, alerting, and evidence gathering.: Collects and correlates security events for monitoring, alerting, and evidence gathering.
- Audit EvidenceAudit EvidenceDocumented information used to demonstrate that a requirement or control is implemented and effective.: Documented information used to demonstrate that a requirement or control is implemented and effective.