Skip to content

Latest commit

 

History

History

README.md

description Security logging architecture resources for log collection, endpoint logs, cloud audit logs, network telemetry, retention, and log source evaluation.

Logging and Security Architecture

Security logging is the foundation for investigations, detections, threat hunting, compliance, and operational troubleshooting. This section focuses on what to collect, how to collect it, where to store it, and how to keep log quality high enough to support real work.

Detection engineering, SIEM rules, Sigma, and alert use cases live under Blue Defense.

{% content-ref url="../blue-defense/event-detection/" %} event-detection {% endcontent-ref %}

Logging Guides

Network hardening articles and unwanted-traffic reduction guidance belong with network detection use cases.

{% content-ref url="../blue-defense/event-detection/detection-use-cases/general-network-traffic.md" %} general-network-traffic.md {% endcontent-ref %}

Logging Data Types

  • Packet Capture - Complete packet-level record. It is the richest network evidence, but storage cost is high.
  • Session / Flow Data - Summarized connection metadata such as source, destination, ports, protocol, bytes, and timestamps.
  • Statistical Data - Metrics and summaries derived from logs or traffic.
  • Packet String Data (PSTR) - Selected strings extracted from network traffic, such as cleartext protocol headers or URLs.
  • Log Data - Raw events generated by systems, applications, devices, cloud platforms, and services.
  • Alert Data - Events produced by detection tools or correlation logic.

Packet capture and NFAT tooling are maintained on the Packet Analysis page.

{% content-ref url="../blue-defense/packet-analysis.md" %} packet-analysis.md {% endcontent-ref %}

Section Map

{% content-ref url="how-to-log.md" %} how-to-log.md {% endcontent-ref %}

{% content-ref url="logging-guide-network-services.md" %} logging-guide-network-services.md {% endcontent-ref %}

{% content-ref url="logging-guide-windows-endpoint-logs.md" %} logging-guide-windows-endpoint-logs.md {% endcontent-ref %}

{% content-ref url="logging-cloud.md" %} logging-cloud.md {% endcontent-ref %}

{% content-ref url="device-discovery-and-asset-inventory.md" %} device-discovery-and-asset-inventory.md {% endcontent-ref %}

{% content-ref url="log-source-evaluation.md" %} log-source-evaluation.md {% endcontent-ref %}

{% content-ref url="logging-user-behavior-monitoring.md" %} logging-user-behavior-monitoring.md {% endcontent-ref %}

Logging System Components

Log Collectors

Collectors gather events from endpoints, servers, network devices, cloud platforms, and applications.

Sysmon configuration and Sysmon-focused detection resources live on the Sysmon page.

{% content-ref url="../blue-defense/event-detection/sysmon.md" %} sysmon.md {% endcontent-ref %}

Log Aggregators

Aggregators receive logs, parse them, normalize fields, enrich events, and route output.

SIEM platforms, enrichment tools, and alerting engines are maintained in Blue Defense.

{% content-ref url="../blue-defense/event-detection/siem-and-enrichment.md" %} siem-and-enrichment.md {% endcontent-ref %}

Log Brokers

A log broker buffers events during bursts or downstream outages.

Storage

Log storage should support integrity, retention, and investigation speed.

  • Hot storage - Recent, frequently searched data.
  • Warm storage - Older data that still needs reasonable search performance.
  • Cold storage - Long-term retention for compliance, historical investigations, and rare lookbacks.
  • WORM - Write Once, Read Many storage for tamper-resistant retention.

Search and Reporting

  • Elasticsearch - Distributed search and analytics engine.
  • Kibana - Elastic search, dashboard, and investigation interface.
  • Splunk - Commercial data platform and SIEM ecosystem.

For query languages used across SIEM and log platforms, see Blue Defense Query Languages.

{% content-ref url="../blue-defense/query-languages.md" %} query-languages.md {% endcontent-ref %}