click below
click below
Normal Size Small Size show me how
Investigating an inc
Investigating an incident
| Question | Answer |
|---|---|
| Security information and event monitoring (SIEM) | Combination of different data sources into one tool that provides real-time analysis of security alerts generated by applications and network hardware |
| Log file | A file that records either events that occur in an operating system or other software that runs, or messages between different users of a communication software |
| Syslog/Rsyslog/Syslog-ng | Variations of syslog which all permit the logging of data from different types of systems in a central repository |
| Journalctl | Mixed command wine, utility used for query and displaying logs from the journald, which is responsible for managing and storing log data on Linux machine |
| NXLog | A multi-platform log management tool that helps to easily identify security risks, policy breaches, or analyze operational problems |
| Rsyslog/Syslog-ng | Linux and Unix |
| NXlog | unix, Linux, and Windows |
| NetFlow | Network protocol system created by Cisco that collects active IP network traffic as it flows in or out of an interface, including its point of origin, destination, volume, and paths on the network |
| Sampled flow (SFlow) | Provide a means for exporting truncated packets, together with interface counters for the purpose of network monitoring |
| Internet protocol flow information export (IPFIX) | Universal standard of export for Internet protocol flow information from routers, probes, and other devices that are used by mediation systems, accounting and billing systems, and network management systems to facilitate services |
| Metadata | Data that describes other data by providing an underlying definition or description by summarizing basic information about data that makes finding and working with particular instances of data easier |
| dashboards | visually display information from various systems, used in security operation centers for a comprehensive overview |