Router and switch logs

Every router or managed switch will have some functionality that allows you to send system and traffic logs to a syslog server. Collecting logs and traffic information from these devices can prove extremely valuable when troubleshooting networking issues or investigating security incidents. Router and switch logs should be centrally stored on a SIEM server to add valuable information to the events correlation engine.

Get Industrial Cybersecurity now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.