One point that is often overlooked is that logs constitute a target.
An attacker who wants to erase traces of their activity may try to:
- delete events
- edit logs
- disable logging
- compromise the log server
- interrupt collection.
MITRE ATT&CK also documents the fact that adversaries can search for or exploit logs and target the logging infrastructure itself. [6]
Therefore, the SIEM must be protected against:
- the removal
- the modification
- unauthorized access
- the alteration
- data loss.
Logging should not become an additional weak point.