Detection

Log Source

A log source is any system that provides security-relevant events to a SIEM or the SOC.

A log source is a system that delivers log data to the SIEM or the SOC platform. Examples include firewalls, servers, identity providers, email services and cloud consoles.

How it works

Every log source generates events in its own format. These are sent to the central platform via agents, interfaces or Syslog. The data is then normalised so that rules can work across different sources. The events a source provides often depend on its configuration. Many systems only log important events after specific configuration.

For example: A company connects Microsoft 365 to its SIEM without including mailbox audit logs. An attacker compromises an account and sets up a forwarding rule. Because this event is missing, the attack remains undetected for weeks. Adding the audit logs would have triggered an existing rule immediately.

What to look out for

  • Prioritise sources by their value for detection: identity, EDR, email, cloud and firewall first.
  • Check the configuration of each source. Important events are often not enabled by default.
  • Monitor whether sources continue to send data. Outages might otherwise go unnoticed.
  • Pay attention to correct timestamps and time zones.
  • Maintain a catalogue of all connected sources with their responsible owners.

Cost and benefit

Many SIEM licences are billed based on data volume. Connecting every source in full is not always worthwhile. It is often sufficient to send specific event types and filter the rest.

Switzerland and regulation

Logs contain personal data. Under the revFADP (revised Federal Act on Data Protection), their processing requires a clear purpose and limited retention. The Swiss Financial Market Supervisory Authority (FINMA) requires sufficient traceability of security-relevant events for financial institutions.

Typical mistakes

A source frequently fails silently after an update and nobody notices. The associated rules then no longer generate any Alerts.

How we implement it

We connect new log sources within five working days and continuously monitor whether all sources are providing data. If a source fails, you receive a notification.

How ANOMAL implements this