5.4.2. Monitoring Activities
💡 First Principle: Monitoring activities are the specific practices that turn raw data collection into security intelligence. Each activity provides a different lens on the environment.
Log aggregation — collecting logs from all sources (servers, network devices, applications, security tools) into a centralized platform. Without aggregation, correlating events across systems is impossible. A SIEM ingests logs via syslog (traditionally UDP 514; syslog over TLS uses TCP 6514), API connectors, or agent-based forwarding. Centralized logging also protects evidence — if an attacker compromises a system and deletes local logs, the copies in the central repository survive. Normalization converts each source's different log format (syslog, Windows events, JSON, vendor firewall formats) into one consistent schema with common fields (timestamp, source, user, action) so events from different devices can be searched and correlated together.
Scanning — regular automated assessment of the environment: vulnerability scans, configuration scans, and compliance scans. Scheduled scanning catches changes between real-time monitoring intervals. Credentialed scans provide the most thorough results because they can examine installed software, patch levels, and local configurations.
Reporting — transforming monitoring data into actionable reports for different audiences: operational dashboards for SOC analysts showing real-time alerts, trend reports for management showing risk posture over time, and compliance reports for auditors documenting control effectiveness. The same data serves different purposes depending on the audience.
Archiving — retaining historical monitoring data for forensic investigations, compliance requirements, and trend analysis. Retention periods vary by regulation (PCI DSS requires one year with 90 days immediately available; HIPAA requires six years). Hot storage allows rapid access to recent data; cold storage archives older data at lower cost. Without proper archiving, you can't investigate incidents that occurred months ago.
Alerting — automated notification when monitoring data exceeds predefined thresholds or matches known attack patterns. Alert tuning is critical — too sensitive produces alert fatigue (analysts overwhelmed by false positives stop investigating), too loose misses real events. Tuning is described with four outcomes: a true positive is an alert on a real attack, a false positive is an alert on benign activity, a false negative is a real attack that raised no alert, and a true negative is benign activity that correctly raised none. A high false-positive rate causes alert fatigue; a false negative is the most dangerous because the attack goes unseen. Effective alerting uses tiered severity levels: informational events log silently, warnings generate tickets, and critical alerts page analysts immediately.
⚠️ Exam Trap: Log aggregation is the foundation of SIEM. Without centralized log collection, you can't correlate events across systems to identify attack patterns that span multiple systems. If logs only exist locally, a compromised system's logs can be tampered with.