Posts

SANS Top 6 Log Reports Reborn!

This story goes back years - many, many years. It starts with “SANS Top 5 Log Reports” [PDF] in 2006, and then continues with me volunteering to update it in 2009. I did a lot of work on it in 2009-2010, but never got it to a stage where I was 100% happy with it.  Then in 2011, I joined Gartner and therefore was unable to finish it. Only in 2012 I found a new author who polished it before handing it to SANS for publication. The document has now been published as “ The 6 Categories of Critical Log Information ” (with a subtitle of “ Top 6 SANS Essential Categories of Log Reports 2013 ”, v 3.01) At its center are these top log report categories: Authentication and Authorization Reports Systems and Data Change Reports Network Activity Reports Resource Access Reports Malware Activity Reports Failure and Critical Error Reports The document can be used to figure out what to log, what to report on and what reports to review for various purposes. So, enjoy! A lot of wo...

Monthly Blog Round-Up – November 2013

Here is my next monthly "Security Warrior" blog round-up of top 5 popular posts/topics this month: “ Why No Open Source SIEM, EVER? ” contains some of my SIEM thinking from 2009. Is it relevant now? Well, you be the judge. “ Simple Log Review Checklist Released! ” is often at the top of this list – the checklist is still a very useful tool for many people. “ On Free Log Management Tools ” is a companion to the checklist ( updated version ) My classic PCI DSS Log Review series is popular as well. The series of 18 posts cover a comprehensive log review approach, useful for building log review processes and procedures, whether regulatory or not. It is also described in more detail in our Log Management book . “ Top 10 Criteria for a SIEM? ” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011. “New SIEM Whitepaper on Use Cases In-Depth OUT!” (dated 2010) presents a whitepaper on select SIEM use cases in depth (the paper link is now R...

Monthly Blog Round-Up – October 2013

Here is my next monthly "Security Warrior" blog round-up of top 5 popular posts/topics this month: “ Why No Open Source SIEM, EVER? ” contains some of my SIEM thinking from 2009. Is it relevant now? Well, you be the judge. “ Simple Log Review Checklist Released! ” is often at the top of this list – the checklist is still a very useful tool for many people. “ On Free Log Management Tools ” is a companion to the checklist ( updated version ) My classic PCI DSS Log Review series is popular as well. The series of 18 posts cover a comprehensive log review approach, useful for building log review processes and procedures, whether regulatory or not. “New SIEM Whitepaper on Use Cases In-Depth OUT!” (dated 2010) presents a whitepaper on select SIEM use cases in depth (the paper link is now RESTORED !) “ Top 10 Criteria for a SIEM? ” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011. In addition, I’d like to draw your attention to a fe...

Monthly Blog Round-Up – September 2013

Here is my next monthly "Security Warrior" blog round-up of top 5 popular posts/topics this month: “ Why No Open Source SIEM, EVER? ” contains some of my SIEM thinking from 2009. Is it relevant now? Well, you be the judge. “ Simple Log Review Checklist Released! ” is often at the top of this list – the checklist is still a very useful tool for many people. “ On Free Log Management Tools ” is a companion to the checklist ( updated version ) “ Top 10 Criteria for a SIEM? ” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011. My classic PCI DSS Log Review series is popular as well. The series cover a comprehensive log review approach, useful for building log review processes and procedures, whether regulatory or not. “New SIEM Whitepaper on Use Cases In-Depth OUT!” (dated 2010) presents a whitepaper on select SIEM use cases in depth (the paper link is now RESTORED!) In addition, I’d like to draw your attention to a few recent post...

Monthly Blog Round-Up – August 2013

Here is my next monthly "Security Warrior" blog round-up of top 5 popular posts/topics this month: “ Why No Open Source SIEM, EVER? ” contains some of my SIEM thinking from 2009. Is it relevant now? Well, you be the judge. “ Simple Log Review Checklist Released! ” is often at the top of this list – the checklist is still a very useful tool for many people. “ On Free Log Management Tools ” is a companion to the checklist ( updated version ) “ Top 10 Criteria for a SIEM? ” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011. “ On Choosing SIEM ” is another old classic (from 2010) that often shows up on my top list; it covers some tips on choosing SIEM tools. Finally, my classic PCI DSS Log Review series is popular as well. They outlined log review approach, useful for building log review processes and procedures, whether regulatory or not. In addition, I’d like to draw your attention to a few recent posts from my Gartner blog : ...

Monthly Blog Round-Up – July 2013

Image
Here is my next monthly "Security Warrior" blog round-up of top 5 popular posts/topics this month: “ Why No Open Source SIEM, EVER? ” contains some of my SIEM thinking from 2009. Is it relevant now? Well, you be the judge. “ Simple Log Review Checklist Released! ” is often at the top of this list – the checklist is still a very useful tool for many people. “ On Free Log Management Tools ” is a companion to the checklist ( updated version ) “ Top 10 Criteria for a SIEM? ” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011. “ On Choosing SIEM ” is another old classic (from 2010) that often shows up on my top list; it covers some tips on choosing SIEM tools. “SIEM Bloggables” has one possible view on higher-level SIEM use cases and basic functionality, and a quick discussion of SIEM user types (circa 2009) Finally, my classic PCI DSS Log Review series is popular as well. They outlined log review approach, useful for building log r...

Monthly Blog Round-Up – June 2013

Here is my next monthly "Security Warrior" blog round-up of top 5 popular posts/topics this month: “ Why No Open Source SIEM, EVER? ” contains some of my thinking from 2009. Is it relevant now? Well, you be the judge. “ Simple Log Review Checklist Released! ” is often at the top of this list – the checklist is still a very useful tool for many people. “ On Free Log Management Tools ” is a companion to the checklist ( updated version ) “ Top 10 Criteria for a SIEM? ” came from one of my last projects I did when running my SIEM consulting firm in 2009-2011. “ On Choosing SIEM ” is another old classic (from 2010) that often shows up on my top list; it covers some tips on choosing SIEM tools. My classic PCI DSS Log Review series is popular as well. The outlined log review approach is useful for building other types of log review processes and procedures, whether regulatory or not. In addition, I’d like to draw your attention to a few recent posts from my Gartner blog : ...