1. Authentication logs
Authentication logs can help identify successful and failed sign-in attempts, unusual authentication behaviour and repeated access failures.
For many organisations these are among the most useful security records because compromised credentials are a common route into business systems.
2. Cloud identity logs
Organisations using cloud identity platforms should consider monitoring relevant sign-in and account activity.
Identity records can provide context around user access, authentication attempts and changes affecting accounts.
3. Web server and application logs
Public-facing websites and applications generate records that may reveal unexpected requests, repeated failures and unusual behaviour.
The value of these logs depends heavily on the application and what information is recorded.
4. Firewall and network security logs
Firewalls and other network security controls can record allowed and denied connections, providing useful visibility into network activity.
5. Security findings need context
An individual event does not automatically mean that an organisation is under attack.
Useful analysis considers factors such as recurrence, surrounding activity, the affected asset and other security evidence.
AssayMark is designed to analyse supported security evidence and combine findings with contextual information rather than presenting every event as an isolated alert.
Explore AssayMark security log analysis →Start with useful visibility
Smaller organisations do not necessarily need to collect every possible log source from day one. A practical approach is to begin with systems that protect important identities, internet facing services and critical business applications.