Source of information

The various log sources will help you to provide security events in different respects. Here are some of the general recommendations of the security monitoring focuses:

Source of information

Security monitoring focuses

Application logs

These are the operational and error logs generated by the application. If the application is a web service, the logs may be included in Apache or nginx logs:

  • Monitor the user activities, especially those activities that involve access to sensitive data
  • Monitor the major changes of user profiles, such as login IPs, abnormal endpoint devices, non-browser connection clients, and concurrent connections from different IP sources
  • Monitor the activities of administration and service ...

Get Hands-On Security in DevOps now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.