Back to Course
Security Information & Event Management (SIEM)
0% Complete
0/27 Steps
-
Logs24 Topics
-
Anti-Spam Solution Logs
-
Authentication Server Logs
-
Authorisation & Access Control Logs
-
Backup Solution Logs
-
Database Logs
-
Directory Services Logs
-
Domain Name Server (DNS) Logs
-
Endpoint Detection & Response (EDR) Logs
-
Firewalls Logs
-
Host Operating System Logs
-
Intrusion Prevention System Logs
-
Mobile Device Management (MDM) Logs
-
Routers Logs
-
Server Operating System (OS) Logs
-
SMTP Logs
-
Network Switches Logs
-
Virtual Private Network (VPN) Logs
-
Web Application Firewall (WAF) Logs
-
Web Application Servers Logs
-
Web Filtering (Proxy) Logs
-
Windows Dynamic Host Configuration Protocol (DHCP) Server Logs
-
Wireless Access Point Logs
-
Host Intrusion Prevention System (HIPS) Logs
-
Virtualization Platform Logs
-
Anti-Spam Solution Logs
-
Detection Optimization
-
Content Management
Participants3
Lesson 1, Topic 14
In Progress
Server Operating System (OS) Logs
Lesson Progress
0% Complete
Windows Server
The Windows Active Directory, Windows DHCP and the Windows DNS servers runs on the Windows Operating System. Therefore it is only necessary to ensure that the Operating System is not under malicious control.
Data Sets
- Event timestamp
- Device type – winevent_nic,30 (type)
- Device class – Host
- Device subclass – Windows
- Message severity level
- Source Interface
- Destination Interface
- User ID’s
- Access group
- Event description
- Successful and failed log-on and log-off;
- Terminal identity or location if possible;
- Records of successful and rejected system access attempts;
- Records of successful and rejected data and other resource
access attempts; - Changes to system configuration;
- Use of privileges;
- Use of system utilities and applications;
- Files accessed and the kind of access;
- Alarms raised by the access control system;
- Activation and de-activation of protection systems,
such as anti-virus systems and IDS/IPS; - Shutdown / reboot of system
Unix Servers
AIX
HP-UX
RHEL
Solaris