Central logging reduces local erasure risk
If logs only exist on the machine that produced them, whoever compromises that machine can rewrite the story.
Clearing local logs is one of the first things an intruder does. Shipping them off the host as they are written means the attacker has to compromise the logging platform as well, which is a meaningfully harder job. It is also the only way to correlate across systems, so it pays twice.
More on Logging and telemetry
- A log records an observation, not objective truthThe shadow, not the thing
- Verbose logging can leak secretsEverything, including that
- Retention determines how far back you can investigateThe line only goes back so far
- Telemetry coverage should map to detection questionsPoint it at the question
- Parsing errors can silently break detectionsSilence is not the same as clear
- High-volume logs can hide high-value eventsBuried by the ordinary
