30% off every course until Sunday, October 11. Our biggest update yet, and we'd like you to try it. Applied automatically at checkout.

Choose your certification
Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

5.9.1. Log Data Sources

💡 First Principle: Logs are the primary evidence source for security investigations. Each log type records different aspects of system and user activity. A complete investigation correlates multiple log sources to reconstruct the full attack timeline — no single log type tells the whole story.

Firewall logs — connection attempts (allowed/denied), source/destination IPs, ports, protocols. Answer: who tried to communicate with what? Firewall logs reveal reconnaissance (port scans), blocked attacks, and exfiltration attempts. They're the first place to look when investigating network-based incidents. A typical entry records the action (ALLOW/DROP), the source and destination address (SRC/DST), the protocol, the destination port (DPT — the service the sender was trying to reach, e.g., 445 = SMB, 3389 = RDP) and, for TCP, the flags (a SYN is a connection attempt; a dropped inbound SYN means no session was established).

Application logs — application-specific events: user logins, transactions, errors, access attempts. Answer: what did users do within the application? Application logs capture business context that infrastructure logs miss — which records were viewed, what transactions were processed, and which queries were executed. Web server access logs record an HTTP status code for every request: 2xx success (200 OK), 3xx redirect, 401 the request lacked valid authentication credentials, 403 forbidden (the server understood the request but a control refused it), 404 not found, 5xx server error (RFC 9110). A run of 401/403/404 responses from one source indicates probing; a 200 on a sensitive path from that same source means a request got through.

IDS/IPS logs — detected threats, alert details, triggered signatures, traffic patterns. Answer: what attacks were detected and what was their nature? IDS/IPS logs provide attack classification and severity that raw network logs lack.

OS logs — system events, authentication attempts, service starts/stops, privilege usage. Windows Event Log (Security, System, Application channels), Linux syslog/journald. Answer: what happened on this system? OS logs capture local authentication events, privilege escalation, and system configuration changes. Key Windows Security event IDs to recognize: 4624 successful logon (logon type 3 = network, type 10 = remote interactive), 4625 failed logon, 4672 special privileges assigned to a new logon (an administrative-equivalent session), 4720 user account created, 4726 user account deleted, 4732 member added to a security-enabled local group such as Administrators, 4740 account locked out, and 1102 audit log cleared (clearing logs is a classic anti-forensics step). Read the IDs as a timeline, not one at a time: privilege grants, account deletions and log clearing that cluster around an unusual logon are classic attacker clean-up.

Endpoint logs — EDR telemetry: process execution, file modifications, network connections, registry changes. Answer: what did this endpoint do? EDR logs provide the most granular view of endpoint activity and are critical for malware investigation and lateral movement detection.

Network logs — NetFlow/sFlow data, DNS queries, DHCP leases, proxy logs. Answer: who communicated with whom and when? Network logs provide session-level metadata without the overhead of full packet capture.

Metadata — data about data: email headers (routing path, sender authentication results), file properties (creation date, author, modification history), document metadata. Often reveals more than the content itself — email headers expose spoofing attempts, and file metadata reveals origin and handling.

⚠️ Exam Trap: Different logs answer different questions. If the exam asks "which log source would reveal unauthorized file modifications?" — endpoint/OS logs. "Which log source shows blocked connection attempts?" — firewall logs. Match the log source to the question being asked.

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder•20 professional certifications