- "I'm sending all logs to Sentinel for now."
- "I have a dashboard, but no one is looking at it."
- "In the audit response, you can say 'we are collecting', but we are not able to use it for operation."
In fact, this is a typical "pitfall" in security operations.
1. Logs are two different things: "collecting" and "using"
The goal of log collection is to "use it for monitoring and analysis".
However, in the field, it is often misunderstood that "collecting = being able to respond to security".
- Azure AD sign-in logs are taken, but suspicious sign-in is not analyzed
- Defender for Endpoint alerts, but no trend analysis
- Firewall and WAF logs are piling up, but no one is searching for them
In this case, the log becomes "dead data".
2. Common "Log Operation Failure Examples"
- "Take everything for now"
Increased storage costs, too much noise to make effective use - Satisfied with just creating a dashboard
No one notices without alert design or search queries - Personal management of the person in charge
When the person in charge is not handed over and the person in charge is absent, the number of "unseen logs" increases.
3. 3 Points to Make Logs a "Living Asset"
(1) Decide on a Purpose and Collect
- "Suspicious sign-in detection", "Tracking email attacks", "Initial confirmation of device compromise", etc.
- Decide what to use it for, then define the scope of log collection
(2) Incorporate Alert Logic
- Leverage Sentinel's KQL queries and Defender rules
- Instead of "look for it when you want to see it", it will be a "notification when it is suspicious"
(3) Leave Knowledge
- Logs and search queries are recorded in tickets and wikis
- Reuse of past cases to change from "logs that are just to be seen" to "logs that can be used"
4. Helping Colorkrew Security
Colorkrew Security can help you turn your logs into a "usable" state in the following ways:
- Microsoft 365/Azure/AWS/GCP log collection design and optimization
- Detection rule and alert design using Sentinel and Defender
- Structure operational knowledge that can be shared by the team
- Cross-sectional monitoring, analysis, and improvement proposals by SOC
It's our job to turn "collected logs" into "meaningful security data."
5. Conclusion
- Logs are not enough to "just collect"
It is meaningless if it cannot be used for monitoring, detection, and analysis - Typical failures are "take it all" and "only the dashboard"
It leads to increased costs, deformity, and dependency - Colorkrew supports "usable log management"
Total support from design, detection rules, and knowledge management
"Logs go from "collecting" to "utilizing".
Colorkrew Security provides log utilization and optimization support services centered on Microsoft Defender and Sentinel.
From initial design to improvement proposals, please leave it to us!