Audit logs need protected access
The logs recording who did what are also the record of what an attacker did, which makes them a target rather than just a resource.
If the same administrators who can act can also delete the record of acting, the audit trail proves very little. Write-once storage, separate access and alerting on log deletion are what turn a log into evidence. It is the difference between a record and a courtesy.
More on Logging and telemetry
- A log records an observation, not objective truthThe shadow, not the thing
- Central logging reduces local erasure riskIt left before you got there
- Verbose logging can leak secretsEverything, including that
- Retention determines how far back you can investigateThe line only goes back so far
- Telemetry coverage should map to detection questionsPoint it at the question
- Parsing errors can silently break detectionsSilence is not the same as clear
