Log Collection: Optimization and Techniques to Detect What You Canât See
ID: f6937497-a201-5e06-a220-9505cb08972e
STIX ID: report--f6937497-a201-5e06-a220-9505cb08972e
Feed Name: ReliaQuest Blog
This blog post summarizes CISA’s M-21-31 event-logging guidance and operational priorities, recommends high-value log sources (ICAM, operating systems, network devices, cloud), and explains how parsing, avoiding duplicate logs, and enabling optional fields improve detection and investigation. It emphasizes a defense-in-depth detection strategy, illustrates with a hypothetical infostealer example, and promotes ReliaQuest GreyMatter as a visibility and detection orchestration solution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
