A company can send millions of events to its SIEM and still have poor visibility.
For what ?
Because some logs can be:
- useless
- incomplete
- misconfigured
- too verbose
- incorrectly time-stamped
- poorly standardized
- devoid of context.
Therefore, a logging strategy must be defined. NIST specifically recommends a structured approach to log management rather than simply accumulating data.