Logs, or event logs, are the files where systems, applications and network devices automatically record what happens: sign-ins, errors, configuration changes or connections. In cybersecurity they are the evidence used to detect attacks and investigate incidents, which is why they are centralized in a SIEM and kept for a defined period.
How TecnetOne handles it: TecnetSOC
event logs, security logs, log management, log retention, audit logs
Related terms
SNMP and NetFlow
SNMP (Simple Network Management Protocol) lets you check the status of routers, switches, servers and printers, such as CPU usage or whether an interface went down. NetFlow records who talks to whom on the network and how much traffic they send. Together they are the foundation of a NOC's network monitoring.
UEBA (user and entity behavior analytics)
UEBA (user and entity behavior analytics) is a technology that learns how a company's users, devices and applications normally behave and raises an alert when something breaks that pattern. For example, it flags a user who downloads thousands of files at 3 a.m., something a fixed rule could miss.
Security incident
A security incident is any event that compromises or threatens the confidentiality, integrity or availability of a company's information or systems, such as unauthorized access, ransomware or the loss of a device with data on it. Not every alert is an incident: it becomes one when real or likely harm is confirmed.
NDR (network detection and response)
NDR (network detection and response) is a technology that continuously analyzes network traffic to detect suspicious behavior, such as lateral movement or communication with malicious servers, and respond to it. It complements EDR because it sees what happens between devices, including those that cannot run an agent.
Cyber kill chain
The cyber kill chain is a model created by Lockheed Martin that splits a cyberattack into seven stages: reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objectives. It helps you see where an attack stands and break the chain as early as possible.
Ready to put this into practice in your operation?
Tell us what you need and a TecnetOne engineer will get back to you.
Talk to an engineerTalk to an engineer
Tell us what you need and we’ll reply the same business day.