Advanced management of logs
As you may know, logs are records of the activities or actions on a given system, OS, or application. They are really important as a source of truth during investigations to determine what can be the cause of downtime, or any other incident.
Best practices state that all logs must be enabled to ensure that you keep track of everything that is happening in your system. Remember, logs are the main source of information during audits or forensic analysis, therefore, you need to make sure they are available for them.
Additionally, nowadays, the cost of storage is really low, so it would be hard for you to justify that a log was disabled to save space.
Another good practice is to keep all logs centralized on an external device, so in case of a full system failure or hard drive crash, you will still be able to retrieve the logs. Furthermore, attackers normally cover their tracks by deleting the logs, but having an external copy of the logs will make it...