
Finding Relevant Alerts, Events and Logs
Source: YouTube · SANS Digital Forensics and Incident Response · published Aug 15, 2025 · 35:11
The speaker addresses the critical challenge of identifying relevant events and logs within vast data sets to effectively prevent and respond to security breaches 0:20.
Key Takeaways:
• The presentation begins by assessing the audience's familiarity with daily log monitoring and incident response practices 0:02.
• A core focus is determining which specific logs and alerts are actually relevant amidst the noise of general system events 0:25.
• The speaker highlights the dual importance of analyzing logs both before a breach occurs for prevention and after for forensic reconstruction 0:46.
• Post-breach analysis involves piecing together the narrative of the attack, which is distinct from the proactive work of identifying relevant indicators beforehand 0:41.
Effective log analysis requires distinguishing signal from noise to support both proactive defense and reactive incident response.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Incident Response. Commonly maps to: Security Operations, Security Assessment and Testing. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Good afternoon everybody. Thank you for having me. I before I start I want to give you maybe a quick like poll. How many people here um actually look at logs like on daily basis? Wow. All right. That's the right room then. So today we're going to talk a little bit about finding relevant events, logs and alerts. So within all of these logs and events that you have, which of them are actually relevant? And a little bit about uh maybe breaches. Have anybody here done incident response with logs and forensics after a breach? Okay, so after a breach, trying to piece together the story is one part, but also before the breach is another part. But imagine you're after a breach. Imagine a breach taken your organization and you've lost some data and you've lost customer I guess respect. You've lost …