Security Monitoring/Logs
Security Monitoring/Logs
Security monitoring is the continuous observation of computers, networks, applications, cloud services, and user activity to detect security threats or suspicious behavior.
Security logs are electronic records of events that happen within those systems. Logs provide the evidence that security teams analyze during monitoring and incident response.
describes continuous monitoring as providing visibility into organizational assets, threats, vulnerabilities, and the effectiveness of security controls.
What Is a Security Log?
A log is like a system’s digital activity record.
A log entry might show:
Plain Text
Date: October 7, 2026
Time: 9:15 AM
User: jsmith
Event: Failed login
Source IP: 192.168.1.50
Result: Access denied
Useful log details include:
What happened
When it happened
Where it happened
What caused the event
Whether the event succeeded or failed
Which user, device, or application was involved
These details support security investigations and help identify unusual activity.
Common Types of Security Logs
Authentication logs
Record sign-in activity, including:
Successful logins
Failed logins
MFA attempts
Account lockouts
Password changes
Repeated failed logins could indicate a brute-force or password-spraying attempt.
Operating-system logs
Record events generated by Windows, Linux, macOS, and other operating systems.
Examples include:
System startup and shutdown
User account changes
Service failures
Software installations
Security-policy changes
Firewall logs
Record permitted and blocked network connections.
Plain Text
Source: 203.0.113.50
Destination: Web Server
Port: 22
Action: Blocked
Network-device logs
Generated by:
Routers
Switches
Wireless access points
VPN gateways
IDS and IPS devices
They may contain connection events, configuration changes, errors, and suspicious traffic alerts.
Application logs
Record activity within applications and services.
Examples:
User activity
Application errors
Administrative changes
API requests
Access to sensitive information
Endpoint security logs
Generated by antivirus, EDR, and endpoint protection systems.
They may record:
Malware detections
Quarantined files
Suspicious processes
Unauthorized application execution
Device-isolation actions
Cloud logs
Record activities in cloud platforms, such as:
Cloud sign-ins
Resource creation or deletion
Permission changes
Administrative actions
Storage access
What Is a SIEM?
SIEM means Security Information and Event Management.
A SIEM collects and analyzes logs from multiple systems in a centralized location.
Plain Text
Firewalls ──────┐
Servers ────────┤
Endpoints ──────┼──> SIEM ──> Alerts and investigation
Applications ───┤
Cloud services ─┘
A SIEM can:
Centralize logs
Search security events
Correlate related activity
Generate alerts
Create reports
Support incident investigations
It can connect separate events that may appear harmless individually.
Correlation example
Plain Text
1. Multiple failed logins
2. Successful login from an unusual location
3. MFA settings changed
4. Large file download
Together, these events could indicate an account compromise.
Security Monitoring Process
1. Collect
Gather logs from important systems, applications, and security tools.
2. Centralize
Send the records to a protected logging platform or SIEM.
3. Analyze
Search for suspicious patterns, policy violations, and unusual behavior.
4. Alert
Notify security personnel when activity meets certain detection conditions.
5. Investigate
Determine whether the alert represents normal activity, a false positive, or a genuine incident.
6. Respond
Contain and remediate confirmed threats.
Plain Text
Collect → Analyze → Alert → Investigate → Respond
Examples of Suspicious Activity
Security monitoring may identify:
Repeated failed logins
Logins at unusual times
Access from unexpected locations
Disabled antivirus software
New administrator accounts
Unexpected firewall changes
Malware detections
Large data transfers
Connections to known malicious systems
Not every unusual event is automatically an attack. Analysts investigate the surrounding context before deciding how to respond.
Log Protection
Logs must be protected because attackers may try to change or delete them.
Important controls include:
Restricting log access
Sending logs to centralized storage
Encrypting log transmissions
Synchronizing system clocks
Defining retention policies
Monitoring for missing or altered logs
Preserving original records for investigations
Centralized logs are especially useful because evidence may remain available even if the affected endpoint is compromised.
Security Monitoring vs Logging
Logging Security monitoringRecords events Reviews and analyzes events
Provides evidence Detects suspicious behavior
May be passive Is an active, ongoing process
Answers what happened Helps determine whether action is needed
Quick memory trick
Plain Text
Logs = Evidence
Monitoring = Watching
SIEM = Collecting and Analyzing
Simple definition: Security logs record activity across systems and networks, while security monitoring analyzes those records to detect suspicious behavior, investigate incidents, and respond to cybersecurity threats.
Subscribe to our newsletter
Sign up with your email address to receive news and updates.