Source of information
The various log sources will help you to provide security events in different respects. Here are some of the general recommendations of the security monitoring focuses:
Source of information | Security monitoring focuses |
Application logs | These are the operational and error logs generated by the application. If the application is a web service, the logs may be included in Apache or nginx logs:
|
Host security, database logs | These mainly rely on the host-based IDS/IPS detection logs, OS, and database logs:
|