5.9.1. Log Data Sources
💡 First Principle: Logs are the primary evidence source for security investigations. Each log type records different aspects of system and user activity. A complete investigation correlates multiple log sources to reconstruct the full attack timeline — no single log type tells the whole story.
Firewall logs — connection attempts (allowed/denied), source/destination IPs, ports, protocols. Answer: who tried to communicate with what? Firewall logs reveal reconnaissance (port scans), blocked attacks, and exfiltration attempts. They're the first place to look when investigating network-based incidents. A typical entry records the action (ALLOW/DROP), the source and destination address (SRC/DST), the protocol, the destination port (DPT — the service the sender was trying to reach, e.g., 445 = SMB, 3389 = RDP) and, for TCP, the flags (a SYN is a connection attempt; a dropped inbound SYN means no session was established).
Application logs — application-specific events: user logins, transactions, errors, access attempts. Answer: what did users do within the application? Application logs capture business context that infrastructure logs miss — which records were viewed, what transactions were processed, and which queries were executed. Web server access logs record an HTTP status code for every request: 2xx success (200 OK), 3xx redirect, 401 the request lacked valid authentication credentials, 403 forbidden (the server understood the request but a control refused it), 404 not found, 5xx server error (RFC 9110). A run of 401/403/404 responses from one source indicates probing; a 200 on a sensitive path from that same source means a request got through.
IDS/IPS logs — detected threats, alert details, triggered signatures, traffic patterns. Answer: what attacks were detected and what was their nature? IDS/IPS logs provide attack classification and severity that raw network logs lack.
OS logs — system events, authentication attempts, service starts/stops, privilege usage. Windows Event Log (Security, System, Application channels), Linux syslog/journald. Answer: what happened on this system? OS logs capture local authentication events, privilege escalation, and system configuration changes. Key Windows Security event IDs to recognize: 4624 successful logon (logon type 3 = network, type 10 = remote interactive), 4625 failed logon, 4672 special privileges assigned to a new logon (an administrative-equivalent session), 4720 user account created, 4726 user account deleted, 4732 member added to a security-enabled local group such as Administrators, 4740 account locked out, and 1102 audit log cleared (clearing logs is a classic anti-forensics step). Read the IDs as a timeline, not one at a time: privilege grants, account deletions and log clearing that cluster around an unusual logon are classic attacker clean-up.
Endpoint logs — EDR telemetry: process execution, file modifications, network connections, registry changes. Answer: what did this endpoint do? EDR logs provide the most granular view of endpoint activity and are critical for malware investigation and lateral movement detection.
Network logs — NetFlow/sFlow data, DNS queries, DHCP leases, proxy logs. Answer: who communicated with whom and when? Network logs provide session-level metadata without the overhead of full packet capture.
Metadata — data about data: email headers (routing path, sender authentication results), file properties (creation date, author, modification history), document metadata. Often reveals more than the content itself — email headers expose spoofing attempts, and file metadata reveals origin and handling.
⚠️ Exam Trap: Different logs answer different questions. If the exam asks "which log source would reveal unauthorized file modifications?" — endpoint/OS logs. "Which log source shows blocked connection attempts?" — firewall logs. Match the log source to the question being asked.