Logs and SIEM for mid-size firms: what to collect and why

KINNEX Team5 min read


After an incident, the first question is “what happened?” Logs are the answer, if they were kept.

What to collect first

  • Identity: sign-ins, failures, privilege changes.
  • Firewall and VPN: allowed and denied traffic, remote logins.
  • Endpoints: security alerts and process activity.
  • Email: delivery, blocked threats and forwarding rules.
  • Cloud administration: changes to settings and permissions.
  • Servers: authentication and key service events.

Centralise

Send logs to one platform so events can be searched together and cannot be erased by an attacker on the source machine.

Retention

Keep enough history to cover a slow breach. Months, not days, for key sources. Align with legal and contractual needs.

Alerts that matter

Impossible travel sign-ins, many failures then success, new administrators, disabled security tools, large data exports, and logins from unusual countries.

Start small

A short list of sources and alerts reviewed weekly beats a huge platform nobody reads. Grow as skills and need grow.

Who watches

Decide who looks at alerts and how fast they respond. This can be an internal team or a managed service under an agreed SLA.

Bring us the site, the challenge or the target outcome

Book an infrastructure assessment, or reach KINNEX directly by phone or WhatsApp.