For teams archiving logs outside the SIEM: how often do you actually query them, and for what reasons?
Hoping I can get some insight from people who send high-volume security logs to cold storage for retention & do investigations. I'm wondering how much one should care about queryability. In the last 90 days say, how many
📄
This source provides headlines only. Use the button below to read the complete article on the original site.
📰 Read the original article on r/cybersecurity
Originally published by r/cybersecurity. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.