Skip to content

SIEM and Log Analysis

Where to find evidence in logs, what to look for, and the tools for collecting and searching them.

Pages

Page Description
Log Review Approach A general method for reviewing logs during an incident
Windows Event Logs Event IDs for logons, account changes, processes, and tampering
Linux Logs Log locations and keywords for authentication and system activity
Web Server Logs Signs of attacks in web server access logs
Network Device Logs Firewall and network device log messages worth reviewing
Syslog The syslog protocol and message format
Sysmon Detailed Windows process, network, and file logging
Splunk Splunk setup basics
DeepBlueCLI Threat hunting in Windows event logs with PowerShell