Lesson 21 / 25
Security Logging and Monitoring
Detect and respond.
Log the right events, alert on patterns
Breaches often go undetected for months because nothing is logged or nobody looks. Log security-relevant events: logins (success and failure), MFA changes, password resets, permission changes, access-control denials, input validation failures and high-value transactions, with user, time, source IP and outcome, but never passwords, tokens or full card numbers. Send logs to a central, tamper-resistant store, alert on suspicious patterns (many failed logins, access denials from one user, admin actions at odd hours), and rehearse incident response.
A structured security event
What a useful audit log entry contains (illustrative).
{
"timestamp": "2026-10-02T07:12:45Z",
"event": "authz.denied",
"user_id": "u_18273",
"resource": "invoice:1002",
"action": "read",
"source_ip": "203.0.113.24",
"request_id": "req_7f3a",
"outcome": "denied"
}Alert on access-control denials
A burst of 403s or 404s from one account iterating IDs is a strong sign of an IDOR probe.
Quick check: Which should never appear in security logs?
- Event type
- Passwords and session tokens
- User ID
- Timestamp
Answer
Passwords and session tokens — Logs must not become a source of secrets.