Skip to main content

Log Management Configuration and Alerts

Example screenshots and guidance for log management evidence

D
Written by Drew Salisbury
Updated over 2 weeks ago

Guidance

Your log management may be covered by multiple tools or a single log management tool may monitor several production systems by itself.

Common CSP-provided log management tools include:

  • AWS CloudTrail, CloudWatch, and GuardDuty

  • Azure Defender, Security Center, and Microsoft Sentinel

  • Google Security Command Center

The following systems are common event monitoring tools:

  • Intrusion detection systems

  • Endpoint management tools

  • Antivirus

  • Log management tools for production systems and infrastructure

Your log management tools monitor your in-scope production systems for events such as:

  • Actions taken by privileged or root users

  • Users accessing sensitive or customer data

  • Invalid login attempts

  • Malicious activity, such as DDoS attacks, brute force logins, etc.

Example Evidence

AWS GuardDuty (Dashboard)

AWS GuardDuty (Alert Notification Configurations)

Google Security Command Center (Dashboard)

Google Security Command Center (Alert Notification Configurations)

Azure Defender (Dashboard)

Azure Defender (Alert Notification Configurations)

Did this answer your question?