Logging of events
Logging of systems activities is a good way to investigate what had happened. Operating systems logs indicate severity ratings of the events.
In various systems access to logs will vary.
If it a single host or low number of hosts, then it is possible to check logs in individual machines.
If number of machines is large, then please think of log aggregation. Aggregated logs must be secure and and access to these log files need to be restricted, as the log files may contain sensitive information.
Comments
Post a Comment