Logs, logs, logs. Ever since I started taking my first steps in the world of secu-
rity, it has been clear that “the log” plays a crucial—and sometimes under-
valued—role in the security management of any IT infrastructure.This fact
alone explains the plethora of tools, applications, and solutions whose only pur-
pose is to generate, analyze, and report on logs. Entire software companies were
built on nothing but a few valid ideas on how to analyze logs or how to pro-
cess and aggregate information coming from different logs. I myself spent a
great deal of time in this field while developing the Microsoft Log Parser tool
to tackle some of these problems.
Despite the proliferation of log-generating, processing, and reporting tools,
and partially because ...