Technical Procedures
Log Analysis Workflow
Framework for effective log analysis to support incident response and threat hunting activities.
Technical Procedures · intermediate · 1-4 hours
Systematic approach to analyzing logs during incident investigation.
Steps
5
01
Log Collection
Gather relevant logs for analysis.
- Identify log sources relevant to the incident
- Export logs covering the incident timeframe
- Ensure log integrity (timestamps, no gaps)
- Organize logs by source and time
SIEM · Log aggregators · Native log export
02
Timeline Establishment
Create initial timeline.
- Normalize timestamps to single timezone (UTC)
- Identify known incident markers
- Mark key events in timeline
- Note any time gaps or missing data
03
Systematic Analysis
Analyze logs systematically.
- Start from known IOCs or events
- Work backwards and forwards in time
- Correlate across log sources
- Document each finding
04
Pattern Identification
Look for attack patterns.
- Search for known attack signatures
- Identify authentication anomalies
- Look for privilege escalation events
- Check for lateral movement indicators
05
Documentation
Document analysis results.
- Create detailed timeline of events
- Document all IOCs discovered
- Preserve relevant log excerpts
- Write analysis narrative
Checklist
- Relevant log sources identified
- Logs exported and preserved
- Timestamps normalized
- Known events marked in timeline
- Correlation across sources completed
- Attack patterns identified
- IOCs extracted
- Timeline documented
- Analysis summary written
Evidence
- Raw log exports
- Normalized timeline
- IOC list
- Analysis notes
- Event narrative