u/AssumptionFlat1707

Information in Logs

Hello,

I am assisting with a PCI assessment and the topic of logging is being discussed in a gap assessment.

I was curious what level of information yall are collecting in your SIEM…. For example we have the event logged in the SIEM but not the whole raw log. Does PCI need us to send the entire raw log to the SIEM, or could you have the event and high levels in the SIEM and be alerted on that and then depending on the issue if warranted investigate the raw logs

reddit.com
u/AssumptionFlat1707 — 10 days ago