Application Log Management and Analysis
Security and audit logging should be defined, implemented and tested for every web application. But what about log management and analysis?
This week Raffael Marty posted an updated item to his blog about a Maturity Scale for Log Management and Analysis. It is an excellent review.
Whilst much of this management and analysis is intended to be external to an application, we need to remember each application needs to record adequate information to feed into these analysis and reporting tools. And why do that? Read the bullet points under return on investment (ROI) at the end of the article. What else? Well perhaps also:
- feedback into the development lifecycle (to improve subsequent patches, versions and other projects)
- greater trust by users
- brand protection
- protection of information assets (not just preventing leaks, but ensuring accuracy and integrity).
Therefore, build adequate logging in from the start. Web server logs are not enough!
Posted on: 09 June 2010 at 16:47 hrs

Comments are filtered automatically and should appear shortly after they been checked.