Using Firewall and Application Logs
Ric Messier · 2017
Log files can be an important place to obtain supporting information for a network forensic investigation. This chapter discusses different types of firewall logs. All of the log systems include different formats for the log files. While there may be different needs when it comes to analyzing the logs, one advantage to log files is they are often just text-based. There are a number of ways to establish a centralized log system. One of the easiest is to just use syslog. Unix-like systems use syslog as the common logging platform. Where syslog runs on Unix-like systems as the de facto logging system, on Windows systems, one can count on the Event Logs and being able to view them using the Event Viewer. The logs that are available on Windows systems fall into two categories: Windows logs and applications and services logs.