Finding Relevant Alerts, Events and Logs

Finding Relevant Alerts, Events and Logs

Source: YouTube · SANS Digital Forensics and Incident Response · published Aug 15, 2025 · 35:11

Incident Response
No ratings yet Log in to rate
Transcript Available
Description

The speaker addresses the critical challenge of identifying relevant events and logs within vast data sets to effectively prevent and respond to security breaches 0:20.

Key Takeaways:
• The presentation begins by assessing the audience's familiarity with daily log monitoring and incident response practices 0:02.
• A core focus is determining which specific logs and alerts are actually relevant amidst the noise of general system events 0:25.
• The speaker highlights the dual importance of analyzing logs both before a breach occurs for prevention and after for forensic reconstruction 0:46.
• Post-breach analysis involves piecing together the narrative of the attack, which is distinct from the proactive work of identifying relevant indicators beforehand 0:41.

Effective log analysis requires distinguishing signal from noise to support both proactive defense and reactive incident response.

Sources:

  • 0:02 Introduction and audience poll on log monitoring habits
  • 0:20 Topic introduction: finding relevant events and logs
  • 0:25 Questioning which logs are actually relevant
  • 0:41 Discussion on incident response after a breach
  • 0:46 Comparing pre-breach and post-breach log analysis

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Incident Response. Commonly maps to: Security Operations, Security Assessment and Testing. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Good afternoon everybody. Thank you for having me. I before I start I want to give you maybe a quick like poll. How many people here um actually look at logs like on daily basis? Wow. All right. That's the right room then. So today we're going to talk a little bit about finding relevant events, logs and alerts. So within all of these logs and events that you have, which of them are actually relevant? And a little bit about uh maybe breaches. Have anybody here done incident response with logs and forensics after a breach? Okay, so after a breach, trying to piece together the story is one part, but also before the breach is another part. But imagine you're after a breach. Imagine a breach taken your organization and you've lost some data and you've lost customer I guess respect. You've lost …