Log Centralization: The End Is Nigh? | by Anton Chuvakin | Anton on Security | Medium
So I woke up the other day [A.C. — well, the other year as this blog has lingered] with the scary thought: what if we will run out of the opportunities to centralize logs for security (and compliance) purposes at some point in the future. Or, as I pithily put it on Twitter: So I wrote some of this and kinda forgot about it for a few months. And then, while at the Gartner Security Summit in June 2023, I saw this: This was my motivation to finish this as an incomplete thought blog. Also, I had a chance to coolly reflect on this and review my past passionate calls to centralize logs (the earliest of my presentations I found was from 2003), let’s see what do we have now? So, for many years, security professionals advocated the approach of collecting logs from places where they are generated and centralizing them (1983) into one or few places. First in flat files, then in databases, later in all sorts of fancy distributed systems. Note that for the sake of this argument, using a distributed
So I woke up the other day [A.C. — well, the other year as this blog has lingered] with the scary thought: what if we will run out of the opportunities to centralize logs for security (and compliance) purposes at some point in the future. Or, as I pithily put it on Twitter: So I wrote some of this and kinda forgot about it for a few months. And then, while at the Gartner Security Summit in June 2023, I saw this: This was my motivation to finish this as an incomplete thought blog. Also, I had a chance to coolly reflect on this and review my past passionate calls to centralize logs (the earliest
Explore this link on the map →