Summary
In this chapter, we discussed the value of firewall logs, the information provided in these logs, and their valuable fields – that is, Log Timestamp, Source IP, Source Port, Destination IP, Destination Port, Source Interface Zone, Destination Interface Zone, Device Action, Sent Bytes, Received Bytes, Sent Packets, Received Packets, Source Geolocation country, and Destination Geolocation country.
In the next chapter, we will discuss how to investigate a list of cyberattacks using firewall logs.