Lesson 21 / 25

Security Logging and Monitoring

Detect and respond.

Log the right events, alert on patterns

Breaches often go undetected for months because nothing is logged or nobody looks. Log security-relevant events: logins (success and failure), MFA changes, password resets, permission changes, access-control denials, input validation failures and high-value transactions, with user, time, source IP and outcome, but never passwords, tokens or full card numbers. Send logs to a central, tamper-resistant store, alert on suspicious patterns (many failed logins, access denials from one user, admin actions at odd hours), and rehearse incident response.

A structured security event

What a useful audit log entry contains (illustrative).

{
  "timestamp": "2026-10-02T07:12:45Z",
  "event": "authz.denied",
  "user_id": "u_18273",
  "resource": "invoice:1002",
  "action": "read",
  "source_ip": "203.0.113.24",
  "request_id": "req_7f3a",
  "outcome": "denied"
}

Alert on access-control denials

A burst of 403s or 404s from one account iterating IDs is a strong sign of an IDOR probe.

Quick check: Which should never appear in security logs?

  • Event type
  • Passwords and session tokens
  • User ID
  • Timestamp
Answer

Passwords and session tokens — Logs must not become a source of secrets.