Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Log files can help you work out what happened during a suspected cyberattack, but no single log is a complete or automatically trustworthy record. Preserve what you have, bring relevant sources together, align their timestamps, and corroborate important clues before deciding whether an attack succeeded. Follow your organization’s incident-response process and involve its security or incident-response team when the investigation exceeds your capability.

What logs can—and cannot—tell you

Useful evidence is often spread across identity systems, endpoints, servers, applications, network devices, and cloud services. Centralized collection makes it easier to compare those records. For example, a firewall may record a source address, an application log may identify the account used, and an identity or system log may help establish whether the attempted action succeeded. CISA recommends logging activity across business systems and monitoring the collected records (CISA’s logging guidance).

Logs are evidence, not a verdict. Records can be missing, incomplete, or altered; a failed login alone does not prove an account was compromised, and an alert may describe an attempted action rather than a successful one. Corroborate significant clues with independent sources and keep facts distinct from hypotheses. OWASP’s Logging Cheat Sheet explains how to select and protect useful application event data.

How to investigate a suspected hack with logs

  1. Set the scope and engage the right people. Note when the concern was raised, which accounts or systems may be affected, and the time window to examine. Coordinate with your organization’s incident-response contacts. NIST’s current incident-response publication is SP 800-61 Rev. 3. The detailed predecessor, Rev. 2, was withdrawn on April 3, 2025, and is superseded by Rev. 3; its publication page remains useful for understanding historical guidance, not as the current revision (NIST SP 800-61 Rev. 2).
  2. Preserve available records early. Save relevant logs and metadata before routine rotation or deletion removes them. Use centrally stored copies when available, restrict access, and handle records under your organization’s evidence and retention policies. The appropriate method depends on the platform and investigation; NIST Rev. 2 discusses copying log data to read-only media, while OWASP advises protecting collected event data against unauthorized access, modification, and deletion.
  3. Collect sources that can answer the same question. Depending on your environment, gather identity-provider and authentication records, endpoint and operating-system logs, application and web-server logs, firewall and network-device records, intrusion-detection alerts, database audit trails, and cloud-service audit logs. CISA recommends coverage for user activity, administrative actions, network traffic, application logins, and system events. Application-specific events can add context that infrastructure logs do not capture.
  4. Align clocks before comparing events. Identify each source’s time zone and timestamp format. Check whether its host was synchronized and account for known offsets. Keep the original timestamp and record any normalized time separately. NIST notes that inconsistent system clocks make event correlation harder.
  5. Start with an indicator and pivot across records. Choose a concrete lead, such as an unexpected successful login, repeated authentication failures, a new privilege assignment, unusual sensitive-data access, or a suspicious configuration change. Search across sources using whatever shared fields are available: account names, source addresses, hostnames, session or interaction IDs, request paths, and timestamps.
  6. Test whether the action succeeded and whether it was legitimate. Look for an independent record of the result, then check whether the behavior fits expected user activity, maintenance, or business context. A firewall connection, for example, does not by itself establish what an application did with it. OWASP recommends recording “when, where, who and what” and identifies authentication and authorization events, administrative actions, sensitive-data access, and configuration changes as useful security events.
  7. Document conclusions with their evidence and confidence. Separate observed events from interpretation. For each conclusion, note which log or other record supports it and how certain it is. NIST Rev. 2 advises correlating multiple indication sources when validating whether an incident occurred.

What to look for in security logs

Prioritize events that relate to the suspected activity rather than searching indiscriminately. OWASP cautions that excessive logging can create noise that obscures useful signals; event selection should reflect the system’s risks.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
  • Authentication: successful and failed sign-ins, especially unusual timing, source, or account patterns.
  • Authorization and privileges: access-control failures, privilege changes, and administrative actions.
  • Sensitive-data access: unexpected reads, exports, or other access to important records.
  • Changes and system behavior: configuration changes, system starts and stops, application errors, and unexpected network connections.
  • Context fields: event time, application or host, account or machine identity, source address, action, affected object, result, and reason where available.

Which fields exist depends on the system and its architecture. Do not put passwords, secrets, or unnecessary sensitive information in logs; OWASP describes both useful event attributes and the need to protect logged data in its logging guidance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Make log review more effective over time

Centralizing records helps responders compare activity across systems, while regular monitoring and targeted alerts can surface high-risk events sooner. Restrict and monitor access to logs, and retain them according to policy so earlier activity—potentially including reconnaissance or related events—remains available when an incident is discovered. CISA outlines these practices in Use Logging on Business Systems.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

NIST’s SP 800-92 Rev. 1 is an initial public draft published October 11, 2023. It frames log management as organization-wide planning and improvement, not a product-specific implementation manual. Its definition covers generating, transmitting, storing, accessing, and disposing of log data. Choose collection and analysis capabilities according to your coverage, retention, access-control, alerting, and investigation needs rather than assuming one tool fits every organization.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display
Rank #3
Sale
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.