Complete Guide to Log Management & Digital Forensics
SIEM Log Sources Explained: What to Collect and Why
Priority SIEM log sources in order: authentication systems (AD, SSO, MFA), cloud audit logs (CloudTrail, Activity Log), firewall and network device logs, endpoint detection (EDR) telemetry, DNS query logs, email gateway logs, and web proxy logs. Start with authentication and cloud audit — these provide the highest detection value per log volume.

Andreas Johansson · Chief Executive Officer
Senior IT management leader with 25 years of experience in Cloud, Security, and Datacenter infrastructure.
The Log Source Decision
Every security monitoring deployment faces the same question: what should we collect? Collecting everything is expensive and generates noise. Collecting too little creates blind spots. The answer lies in prioritising log sources by their detection value — what threats does each source enable you to detect?
Priority 1: Authentication and Identity
Authentication logs are the highest-value security data source. Nearly every attack involves credential usage — compromised passwords, stolen tokens, or abused service accounts.
- Active Directory / LDAP. Login events, failed authentication, account lockouts, password changes, group membership changes, and Kerberos ticket events. Critical for detecting brute-force attacks, credential stuffing, pass-the-hash, and Golden Ticket attacks.
- SSO / Identity Provider. OAuth token events, SAML assertions, MFA verification, conditional access decisions, and session management. Essential for detecting account takeover and identity-based attacks in cloud-first environments.
- VPN and Remote Access. Connection events, authentication success/failure, source IP addresses, and session duration. Reveals unauthorised remote access and geographic impossibility (logins from multiple countries simultaneously).
Priority 2: Cloud Audit Trails
Cloud audit logs record every API call and configuration change in your cloud environments — making them essential for detecting cloud-specific threats.
- AWS CloudTrail. Every AWS API call: who called what service, from where, and what changed. Detects IAM policy changes, S3 bucket exposure, security group modifications, and resource creation/deletion.
- Azure Activity Log. Azure control plane operations: resource creation, configuration changes, role assignments, and policy modifications. Supplemented by Azure AD sign-in logs for identity activity.
- GCP Cloud Audit Logs. Admin activity, data access, and system event logs across all GCP services. Detects configuration changes, data access patterns, and IAM policy modifications.
Priority 3: Network Perimeter
Network logs reveal connections that cross trust boundaries — inbound attacks, outbound command-and-control, and data exfiltration.
- Firewall logs. Connection allow/deny events, source/destination IPs and ports. Detects scanning, blocked attack attempts, and unexpected outbound connections.
- Web proxy logs. HTTP/HTTPS requests, URLs, user agents, and response codes. Detects malicious downloads, command-and-control beacons, and policy violations.
- DNS query logs. Domain name resolution requests. Detects connections to malicious domains, DNS tunnelling for data exfiltration, and domain generation algorithm (DGA) activity.
Priority 4: Endpoint Telemetry
EDR and endpoint logs provide visibility into activity on individual systems:
- EDR telemetry. Process execution, file modifications, registry changes, network connections. Detects malware execution, lateral movement, and persistence mechanisms.
- Operating system logs. Windows Security Event Log, Linux auth.log and auditd. Authentication, privilege escalation, service changes, and system events.
Priority 5: Email and Application
- Email gateway logs. Inbound/outbound email, attachment scanning results, URL analysis, spam classification. Detects phishing campaigns, malicious attachments, and business email compromise.
- Application logs. Web server access logs, application-specific audit logs. Detects web application attacks, API abuse, and application-level data access.
Implementation Strategy
Don't try to collect everything at once. Build log collection in priority order:
- Week 1-2: Authentication and cloud audit logs — highest detection value
- Week 3-4: Firewall and DNS logs — network visibility
- Week 5-6: Endpoint telemetry — host-level visibility
- Week 7-8: Email and application logs — additional context
How SeqOps fits
SeqOps keeps your findings and alerts from connected cloud accounts and servers in one place, tracks each alert from New to Resolved, and lets you export results as CSV, PDF or Excel or send scheduled PDF reports to your team. It doesn't replace a log management or forensics tool.