Logs and SIEM for mid-size firms: what to collect and why
KINNEX Team5 min read
After an incident, the first question is “what happened?” Logs are the answer, if they were kept.
What to collect first
- Identity: sign-ins, failures, privilege changes.
- Firewall and VPN: allowed and denied traffic, remote logins.
- Endpoints: security alerts and process activity.
- Email: delivery, blocked threats and forwarding rules.
- Cloud administration: changes to settings and permissions.
- Servers: authentication and key service events.
Centralise
Send logs to one platform so events can be searched together and cannot be erased by an attacker on the source machine.
Retention
Keep enough history to cover a slow breach. Months, not days, for key sources. Align with legal and contractual needs.
Alerts that matter
Impossible travel sign-ins, many failures then success, new administrators, disabled security tools, large data exports, and logins from unusual countries.
Start small
A short list of sources and alerts reviewed weekly beats a huge platform nobody reads. Grow as skills and need grow.
Who watches
Decide who looks at alerts and how fast they respond. This can be an internal team or a managed service under an agreed SLA.