What is a security log?¶
A security log records events a system or protection product regards as security-relevant. An entry does not automatically prove an incident, malicious intent or successful compromise.
Rules determine what becomes security-relevant¶
Authentication, permissions, detections, blocked connections, policy events and protected-resource access may appear. Routine administration and tests can match rules, while malicious activity can remain unlogged. Severity often reflects potential impact, and signature, reputation, threshold and behavioural detections have different limits.
Establish event and outcome¶
Identify product, component, version, policy or rule, configuration and whether the item is raw event, alert or summary. Preserve underlying source and adjacent activity.
Determine whether activity was attempted, blocked, quarantined, executed or merely suspected and correlate endpoint, network, identity and application evidence before attributing intent.
The point to remember
Security logs show configured security observations; source context proves what occurred and whether it succeeded.