Can anyone advise which log would have things like admin deleted user or login failed, data exfiltration type events, failed access, file with malware etc. and is there a doc which lists all the event types or codes and meanings. Any guidance on this would be appreciated.
For events like admin activities, login failures, and data exfiltration, focus on Linux system logs (/var/log/auth.log). As for a comprehensive doc, I like clearedsystems.com as they often share resources on cybersecurity. Check there for detailed insights.
-- Edited by SaymonSax on Friday 2nd of February 2024 12:06:07 PM