Log management maturity



A sane approach to log collection is essential to successful deployment. This means in practice: don't get in there with a belief of installing a box and you're all set and compliant to whatever your initial goal was. This is very far from reality and even further from what could be true.

In real life you will want to proceed with utmost care and tread with baby steps in mind. If you know what you have in means of hardware, operating systems, applications and most importantly have a deep understanding of what you are logging and know various I/O peaks you might be able to take more of a wholesale approach in implementing log collection. Another approach (a more common scenario) for a shop that does not quite know what they have, what they need and how I/O will interfere (or not) with their existing environment would be baby steps, introducing one log source at the time, analyzing the results, and when you're happy, go on to the next log source.

Let's start with a basic maturity ladder for log collection. The purpose of this ladder is to give an idea of where you are to begin with. When you have decided upon which level you are at right now, you also know where you need to go, and what will be needed to climb up a notch on that ladder. The ladder is divided into six levels:

1. Log ignorance
2. Log collection
3. Log investigation
4. Log reporting
5. Log review
6. Log monitoring

There is no right or wrong level to be at, the most important thing is that you have a feeling of where you are aiming. This goal may be set by you, your bosses, your company's board or regulatory requirements such as PCI-DSS, HIPAA, SOX, Basel, or even local laws.

As you will see all of these steps will be explained in a very loose, and in some cases a bit ranting, way with a feel of "every day usage" feeling. At the end, I will post links and thanks to those who has contributed to my thoughts and conclusions, as well as pointers to where to find software (or hardware appliances) for your purposes. Please pop in for comments and suggestions :-)

Logging is king!

Comments

Popular posts from this blog

Overhead lines

Links for August 19th 2009

R.I.P. Google Reader