{"id":1387,"date":"2022-06-22T14:09:04","date_gmt":"2022-06-22T07:09:04","guid":{"rendered":"https:\/\/dt-corp.com.vn\/?p=1387"},"modified":"2022-06-22T14:12:00","modified_gmt":"2022-06-22T07:12:00","slug":"are-you-making-any-of-these-mistakes-with-your-log-analytics","status":"publish","type":"post","link":"https:\/\/dt-corp.com.vn\/?p=1387","title":{"rendered":"Are You Making Any of These Mistakes with Your Log Analytics?"},"content":{"rendered":"<p>&nbsp;<\/p>\n<div class=\"page-header\">\n<div class=\"ps-grid\">\n<div class=\"ps-grid__inner\">\n<div class=\"ps-grid__cell ps-grid__cell--span-9-desktop\">\n<div class=\"post-header\">\n<p class=\"post-excerpt post-header__subtitle\">Security log analytics is pretty much SecOps table stakes. Learn how you can avoid a few common mistakes that could hold you back from leveraging this goldmine.<\/p>\n<div class=\"post-thumb\">\n<div class=\"positioner\"><img loading=\"lazy\" decoding=\"async\" class=\"webfeedsFeaturedVisual wp-post-image\" src=\"https:\/\/16kqg2tgn1u4ew0tl3ybl9pr-wpengine.netdna-ssl.com\/wp-content\/uploads\/2022\/06\/blog-tl-perspectives-fast-security-logs-by-andy-stone-768x432.jpg\" sizes=\"auto, (max-width: 768px) 100vw, 768px\" srcset=\"https:\/\/16kqg2tgn1u4ew0tl3ybl9pr-wpengine.netdna-ssl.com\/wp-content\/uploads\/2022\/06\/blog-tl-perspectives-fast-security-logs-by-andy-stone-768x432.jpg 768w, https:\/\/16kqg2tgn1u4ew0tl3ybl9pr-wpengine.netdna-ssl.com\/wp-content\/uploads\/2022\/06\/blog-tl-perspectives-fast-security-logs-by-andy-stone-728x410.jpg 728w, https:\/\/16kqg2tgn1u4ew0tl3ybl9pr-wpengine.netdna-ssl.com\/wp-content\/uploads\/2022\/06\/blog-tl-perspectives-fast-security-logs-by-andy-stone-1400x788.jpg 1400w, https:\/\/16kqg2tgn1u4ew0tl3ybl9pr-wpengine.netdna-ssl.com\/wp-content\/uploads\/2022\/06\/blog-tl-perspectives-fast-security-logs-by-andy-stone-1536x864.jpg 1536w, https:\/\/16kqg2tgn1u4ew0tl3ybl9pr-wpengine.netdna-ssl.com\/wp-content\/uploads\/2022\/06\/blog-tl-perspectives-fast-security-logs-by-andy-stone-2048x1152.jpg 2048w, https:\/\/16kqg2tgn1u4ew0tl3ybl9pr-wpengine.netdna-ssl.com\/wp-content\/uploads\/2022\/06\/blog-tl-perspectives-fast-security-logs-by-andy-stone-150x84.jpg 150w, https:\/\/16kqg2tgn1u4ew0tl3ybl9pr-wpengine.netdna-ssl.com\/wp-content\/uploads\/2022\/06\/blog-tl-perspectives-fast-security-logs-by-andy-stone-2000x1125.jpg 2000w\" alt=\"Log Analytics\" width=\"768\" height=\"432\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"ps-grid__cell ps-grid__cell--span-3-desktop\">\n<div class=\"blog-sidebar\">\n<div class=\"blog-sidebar__widget\">\n<div class=\"post-author\"><\/div>\n<\/div>\n<div class=\"blog-sidebar__taglist\">\n<p>Security log analytics is pretty much SecOps table stakes these days. But that doesn\u2019t mean every organization is getting it right. Before, I discussed <a href=\"https:\/\/blog.purestorage.com\/perspectives\/security-logs-3-reasons-you-cant-survive-without-them\/\" target=\"_blank\" rel=\"noopener\">three reasons you can\u2019t live without security logs<\/a>\u2014here, I\u2019ll talk about a few common mistakes that could be holding you back from leveraging this goldmine of data to its fullest potential.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"page-content\">\n<div class=\"ps-grid\">\n<div class=\"ps-grid__inner\">\n<div class=\"ps-grid__cell ps-grid__cell--span-9-desktop\">\n<div class=\"post-content\">\n<h2><strong>Fast Security Logs Are the Key to Beating the Clock<\/strong><\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-106664 aligncenter\" src=\"https:\/\/16kqg2tgn1u4ew0tl3ybl9pr-wpengine.netdna-ssl.com\/wp-content\/uploads\/2022\/06\/log-analytics.png\" sizes=\"auto, (max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/16kqg2tgn1u4ew0tl3ybl9pr-wpengine.netdna-ssl.com\/wp-content\/uploads\/2022\/06\/log-analytics.png 512w, https:\/\/16kqg2tgn1u4ew0tl3ybl9pr-wpengine.netdna-ssl.com\/wp-content\/uploads\/2022\/06\/log-analytics-150x71.png 150w\" alt=\"log analytics\" width=\"512\" height=\"243\" \/><\/p>\n<p>When hackers gain access to a network, they can linger for days or even weeks before you know they\u2019re there. While undetected, they\u2019re gathering admin credentials and doing recon. Security logs\u00a0<i>can<\/i>\u00a0alert you to an intruder, but many aren\u2019t fast enough. Or, they don\u2019t gather quite enough clues to raise a red flag. When they do, it\u2019s often too late and the damage has already been done.<\/p>\n<p>That\u2019s why fast security log analytics is a key part of any defense strategy\u2014the \u201c<a href=\"https:\/\/blog.purestorage.com\/perspectives\/5-ways-to-address-data-security-gaps-before-an-attack\/\" target=\"_blank\" rel=\"noopener\">before<\/a>\u201d of an attack that is as critical as the \u201c<a href=\"https:\/\/blog.purestorage.com\/perspectives\/a-6-point-plan-for-the-during-of-a-data-breach\/\" target=\"_blank\" rel=\"noopener\">during<\/a>\u201d and the \u201c<a href=\"https:\/\/blog.purestorage.com\/perspectives\/5-ransomware-recovery-steps-to-take-after-a-breach\/\" target=\"_blank\" rel=\"noopener\">after<\/a>.\u201d Let\u2019s take a look at what fast security logs are, why they matter, and how you can start using them at your organization.<\/p>\n<h2><strong>What Are Fast Security Logs And Why Do They Matter?<\/strong><\/h2>\n<p>Security log analytics consists of log data generated around the clock by network systems, end user behaviors and actions, and endpoint activity, and security monitoring systems. Log and event data is spread out everywhere across an enterprise and can be found in files, applications, sensors, network events, virtual machines, operating systems, clouds, security devices, operating systems, and more.<\/p>\n<p>Security log analytics can help make sense of all this data and help to power:<\/p>\n<ul>\n<li aria-level=\"1\">Rapid experimentation<\/li>\n<\/ul>\n<ul>\n<li aria-level=\"1\"><b>Threat hunting<\/b><\/li>\n<li aria-level=\"1\">Purple teaming exercises<\/li>\n<\/ul>\n<p>In terms of threat hunting, specifically, security logs are only valuable\u00a0<i>if<\/i>\u00a0they\u2019re fast and comprehensive. Simply put: You need your logs and underlying systems to be fast if they\u2019re actually going to help you defend against cyberattacks. Otherwise, you\u2019re looking for a needle in a haystack on borrowed time.<\/p>\n<h2><strong>How Do We Define \u201cFast?\u201d<\/strong><\/h2>\n<p>You can measure the speed of security log analytics in terms of terabytes per second or by a more arbitrary (but also more relevant) measure: \u201c<b>breakout time<\/b>.\u201d<\/p>\n<p>Breakout time is the time between when an attacker breaks into your system, gaining access as a regular user, and when they elevate that user privilege to \u201cadmin.\u201d With admin privileges, they can really start to wreak havoc. We used to measure breakout time in days or hours. Today, it\u2019s down to minutes\u2014about\u00a0<b>90 minutes<\/b>,\u00a0to be exact. That\u2019s how long you have to find that needle in the haystack.<\/p>\n<p>Speed and performance of security logging systems determine how quickly you\u2019re able to:<\/p>\n<ul>\n<li aria-level=\"1\">Detect and respond to threats in near real time<\/li>\n<li aria-level=\"1\">Identify anomalies in historic and behavioral data<\/li>\n<li aria-level=\"1\">Leverage advanced algorithms and AI to detect never-before-seen threats<\/li>\n<\/ul>\n<p>However, too many organizations miss out on these capabilities due to a few common mistakes.<\/p>\n<h2><strong>Common Fast Logging Mistakes\u00a0<\/strong><\/h2>\n<p><a href=\"https:\/\/blog.purestorage.com\/perspectives\/security-logs-3-reasons-you-cant-survive-without-them\/\" target=\"_blank\" rel=\"noopener\">Effective security logs<\/a>\u00a0rely on two things:\u00a0<b>fast analytics platforms<\/b>\u00a0and\u00a0<b>fast data storage solutions<\/b>. Trying to detect anomalies without those two components is nearly impossible\u2014but that\u2019s not all. Other common mistakes companies make with their security logs include:<\/p>\n<ol>\n<li><b>Not enough logs, and therefore, limited visibility.<\/b><\/li>\n<\/ol>\n<p>Think of your security logs as windows into everything going on within your systems. If you\u2019re looking through a peephole, your view is too narrow. But, see things through a big pane of glass and you\u2019ll get a more holistic view of everything that\u2019s going on. Put simply, everything should be logged at all times.<\/p>\n<ol start=\"2\">\n<li><b>Logs that aren\u2019t correlated across networks, endpoints, and end users.\u00a0<\/b><\/li>\n<\/ol>\n<p>Your logs are only as valuable as they are informative. To be truly useful, they need to be able to correlate events occurring in many different areas of your ecosystem, including cross-referencing across the network, endpoints, and end users.<\/p>\n<ol start=\"3\">\n<li><b>A back-end infrastructure that isn\u2019t fast enough to support advanced analytics.<\/b><\/li>\n<\/ol>\n<p>Without a powerful data storage back end, the reality is, even successful correlation queries will be too slow to reveal threats in time. When you\u2019re looking for that needle in the haystack, think of incredibly performant data storage as a magnet to draw that needle to the top. It makes quick work of threat detection and analytics. But if your storage is slow, your data lake too immense, or your queries poorly written, it can take hours or even days of research to pinpoint an issue or potential threat.<\/p>\n<blockquote><p><i>When you\u2019re looking for that needle in the haystack, think of incredibly performant data storage as a magnet to draw that needle to the top. It makes quick work of threat detection and analytics. \u2013 Andy Stone, CTO-Americas, Pure Storage<\/i><\/p><\/blockquote>\n<h2><strong>How to Supercharge Security Log Analytics<\/strong><\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-106669 aligncenter\" src=\"https:\/\/16kqg2tgn1u4ew0tl3ybl9pr-wpengine.netdna-ssl.com\/wp-content\/uploads\/2022\/06\/supercharge.png\" sizes=\"auto, (max-width: 512px) 100vw, 512px\" srcset=\"https:\/\/16kqg2tgn1u4ew0tl3ybl9pr-wpengine.netdna-ssl.com\/wp-content\/uploads\/2022\/06\/supercharge.png 512w, https:\/\/16kqg2tgn1u4ew0tl3ybl9pr-wpengine.netdna-ssl.com\/wp-content\/uploads\/2022\/06\/supercharge-150x97.png 150w\" alt=\"supercharge\" width=\"512\" height=\"332\" \/><\/p>\n<p>For security log analytics to deliver the firepower you need to combat cyberattacks, they should include:<\/p>\n<ul>\n<li aria-level=\"1\">Real-time processing with search and query performance that\u2019s reproducible, no matter the log size. This requires high throughput, low latency, and consistent performance finely tuned for any scenario or scale.<\/li>\n<li aria-level=\"1\">Embedded data reduction and on-demand scaling to log and retain more data for longer, for the richest possible analysis.<\/li>\n<li aria-level=\"1\">Easy scalability for multiple workloads, concurrent queries, and variable data patterns to accommodate fast analysis of multi-petabyte data sets.<\/li>\n<li aria-level=\"1\">Multiple logs that correlate data across networks, endpoints, and end users.<\/li>\n<li aria-level=\"1\">Management simplicity to let you easily build new queries and reduce complexity.<\/li>\n<\/ul>\n<p>Pure Storage\u00ae offers the fastest analytics processing available for fast logs, especially if you\u2019re already using platforms like\u00a0<a href=\"https:\/\/www.purestorage.com\/partners\/technology-alliance-partners\/splunk.html\" target=\"_blank\" rel=\"noopener\">Splunk\u00a0<\/a>and\u00a0<a href=\"https:\/\/www.purestorage.com\/partners\/technology-alliance-partners\/elastic.html\" target=\"_blank\" rel=\"noopener\">Elastic<\/a>. With unified fast file and object storage (UFFO) from Pure, you\u2019ll achieve the speed and agility IT and SecOps teams need today by un-siloing data, separation of compute and storage, and elastic, automated infrastructure so you can focus on insights, not operations.<\/p>\n<p>Remember\u2014security log analytics is the most important tool in your toolbox for the\u00a0<b>before<\/b>\u00a0of a cyberattack. Time is limited, so you must make the greatest impact possible in the shortest window possible.<\/p>\n<p>Bottom line: In today\u2019s threat landscape, you can\u2019t afford for your log analytics to be slow.<\/p>\n<p><a href=\"https:\/\/events.goldcast.io\/e\/ee7396ca-5feb-476d-af78-03a05659e025\/eventbooth2\/9bf86ed3-9a05-43ba-b67a-3c8e039d5e95\" target=\"_blank\" rel=\"noopener\">Watch the on-demand Pure\/\/Accelerate session, \u201cSpeed Security Analytics at Any Scale<\/a>.\u201d<\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<\/div>\n<div class=\"ps-grid__cell ps-grid__cell--span-3-desktop\">\n<div class=\"blog-sidebar\">\n<div class=\"blog-sidebar__widget\">\n<div class=\"sidebar-cta\">\n<h4 class=\"sidebar-cta__headline\">Protect Your Organization<\/h4>\n<p>Learn how to speed up security analytics at any scale with unified fast file and object storage.<\/p>\n<p><a class=\"btn btn--white\" href=\"https:\/\/events.goldcast.io\/e\/ee7396ca-5feb-476d-af78-03a05659e025\/eventbooth2\/9bf86ed3-9a05-43ba-b67a-3c8e039d5e95\">Watch the Session<\/a><\/p>\n<\/div>\n<div><strong>By: <a href=\"https:\/\/by.com.vn\/URk5VU\">Andy Stone<\/a><\/strong><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"page-comments\">\n<div class=\"ps-grid\">\n<div class=\"ps-grid__inner\">\n<div class=\"ps-grid__cell ps-grid__cell--span-9-desktop\">\n<div class=\"post-comments\"><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p class=\"tx-excerpt\">&nbsp; Security log analytics is pretty much SecOps table stakes. Learn how you can avoid a few common mistakes that could hold you back from leveraging this goldmine. Security log analytics is pretty","protected":false},"author":3,"featured_media":1388,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[13],"tags":[],"class_list":["post-1387","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/dt-corp.com.vn\/wp-content\/uploads\/2022\/06\/blog-tl-perspectives-fast-security-logs-by-andy-stone-768x432-1.jpg","_links":{"self":[{"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/posts\/1387","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1387"}],"version-history":[{"count":2,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/posts\/1387\/revisions"}],"predecessor-version":[{"id":1390,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/posts\/1387\/revisions\/1390"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=\/wp\/v2\/media\/1388"}],"wp:attachment":[{"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1387"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1387"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dt-corp.com.vn\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1387"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}