Once you have visibility into your production environment by gaining access to information system data and log sources, it is now time to begin performing log reduction and log analytics:
- Log reduction: Implementing log reduction takes all of the available information that can be understood from a log source and reduces it down to only the information necessary to determine if a threat exists on the network
- Log analytics: The automated and human interactions associated with log review and the work necessary to establish analytics automation:
- The indicator of compromise (IOC) analysis, such as:
- Internet domain names
- File hashes
- Geographic location irregularities
- IP addresses
- Privileged user account anomalous ...