8
Network Firewall Logs Analysis
The network firewall is one of the most critical network security controls deployed in the network. It is necessary to manage and control the communications in the network, and to do so, the network firewall usually takes a strategic position, allowing it to have insight and visibility into the traffic between the different zones and subnets. As a SOC analyst, you should take advantage of the firewall’s position, be aware of the logs provided by the firewall, and be able to analyze it to investigate cyber incidents.
The objective of this chapter is to learn the value of firewall logs and the information provided by these firewall logs, and understand the valuable fields of the firewall logs, such as the Log Timestamp, ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access