Logging and monitoring
Logging and monitoring are the most important techniques in today's threat landscape. Logs and monitoring data is the basis for later analysis and behavioral analysis of network traffic, user actions, failed processes, and more. The more data you have, the more likely you are to find an anomaly or a pattern that can be used for automated threat analysis.
But as data is nothing without former analysis, the visualization and analytic tools are as important as the behavioral threat detection tools.
Azure Logs
Azure collects lots of logs for you by default. There is a central dashboard for viewing logs and events called Monitor. The Monitor is still in preview, but in my opinion it is the best organized place to manage logs and diagnostics.
There are three main categories of logs that are collected. These are under the EXPLORE
point in the Azure Monitor.
- Activity log: The activity log keeps track of all actions that are happening on Azure. It logs all activities no matter if...