Navigating the Data Stream without Boiling the Ocean: Case Studies in Effective Log Management Dr. Anton Chuvakin: IANS Faculty Panel members from large organizations using log management/SIEM tools [names removed due to not having permission to post them See IANS site http://www.iansresearch.com for full details]
Agenda SIEM and Log Management Common Pitfalls and Lessons Discussion Questions Q&A Webcast Q&A posted at http://chuvakin.blogspot.com/search/label/questions Sponsor Presentation
SIEM and Log Management LM: Log Management Focus on all uses for logs SIEM: Security Information and Event Management Focus on security use of logs and other data
Top Log Management Mistakes Not logging at all. Approaching logs in silo’ed fashion Storing logs for too short a time Prioritizing the log records before collection Ignoring the logs from applications Not looking at the logs Only looking at what youknow is bad Thinking that compliance=log storage
Discussion Questions: What to Log? What do you log? Devices? Systems? Applications? What approach was taken to determine ‘what to log?’? What process was followed? What data are you logging and why are you logging it? How you deal with custom log formats, e.g from custom applications? Structured and unstructured data: do you parse all or only index some data? Retention policy: how? What? For how long?
Discussion Questions: How to Do Log Management? What are you doing with the log data? What do you review? What motivated you to review logs? What logs are looked at periodically? What logs are looked at only after an incident? What tools used for log review? LM or SIEM? Who reviews logs? What roles are looking at logs? Who uses each of the tools?
Discussion Questions: Tools Choosing tools How were the tools chosen? What are the top 3 requirements that were used? Operating tools: What each tool does? SIEM and LM Joint SIEM and LM architecture Logger in front? Other architecture choices? Key: How to figure what to filter from LM to SIEM? From correlation rules? Or devices? or use cases?
Discussion Questions: Compliance and Use Cases Investigative use case Any lessons learned on how to investigate incidents using log data?