Sort log sources by the decision they support
Categorize SIEM log sources by the operational decision they most directly support.
Place each log source in the decision bucket it most directly supports during SIEM operations. Detection Scoping Containment Recovery Endpoint process creation with parent process and command line. Identity provider active sessions, MFA method, and token issuance. DNS and proxy logs showing destinations contacted after suspicious execution. Backup-console audit logs and restore-job history. Cloud object-read and object-list audit events for sensitive storage. Admin role changes and group membership modification events. Firewall quarantine action log and network access control isolation record. Configuration baseline and post-incident integrity check results.
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in