# Security Logging and Monitoring — OWASP Top 10

Source: https://www.skillbyai.com/en/owasp-top-10/u-logging

> Detect and respond.

## Log the right events, alert on patterns

Breaches often go undetected for months because nothing is logged or nobody looks. Log security-relevant events: logins (success and failure), MFA changes, password resets, permission changes, access-control denials, input validation failures and high-value transactions, with user, time, source IP and outcome, but **never** passwords, tokens or full card numbers. Send logs to a central, tamper-resistant store, alert on suspicious patterns (many failed logins, access denials from one user, admin actions at odd hours), and rehearse incident response.

## A structured security event

What a useful audit log entry contains (illustrative).

```json
{
  "timestamp": "2026-10-02T07:12:45Z",
  "event": "authz.denied",
  "user_id": "u_18273",
  "resource": "invoice:1002",
  "action": "read",
  "source_ip": "203.0.113.24",
  "request_id": "req_7f3a",
  "outcome": "denied"
}
```

## Alert on access-control denials

A burst of 403s or 404s from one account iterating IDs is a strong sign of an IDOR probe.

**Quiz:** Which should never appear in security logs?

- [ ] Event type
- [x] Passwords and session tokens
- [ ] User ID
- [ ] Timestamp

*Answer:* Passwords and session tokens. Logs must not become a source of secrets.
