Summary
The authors would like to acknowledge the industry partners that contributed to this publication. In this publication, the authoring agencies provide cyber security practitioners with detailed recommendations on the logs that should be prioritised for ingestion by a Security Information and Event Management (SIEM) platform. The recommendations in this publication should be treated as generic advice; each organisation should tailor the collection, centralisation, and analysis of logs to its specific environment and risk profile. Practitioners should also adopt an approach of gradually building up the number and types of data sources ingested by the SIEM, rather than adding them all at once. The authoring agencies recommend referring to vendor specific guidance where available for information tailored to each operating system. This publication is therefore generally intended for the team/s responsible for establishing and maintaining their organisation’s SIEM.