20–30 min Updated

Logging and Monitoring

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

Comprehensive logging and monitoring will tell you what your site is doing at runtime, which is key to spotting security events.

Prevalence
Common
Exploitability
Moderate
Impact
Harmful

What are logging and monitoring failures?

Logging and monitoring failures are a detection weakness in which an application does not record security events, or nobody reviews the records. They are not an attack in themselves. Without logs and alerts for events such as failed logins and access control errors, attackers can probe and compromise a system for months without being noticed.

What you'll learn

  • Which security events to log, and what to keep out of your logs
  • How log levels, central log servers and retention fit together
  • How metrics, error reporting and alerts reveal an attack in progress

Where this lesson counts

OWASP Top 10

  • Logging and Monitoring lab

    Walk through what a web application should record at runtime and how to use it: server and application logs, log levels, central log servers and retention, then metrics, error reporting, alerts and a response plan. Includes what to keep out of your logs.

  • How to prevent Logging and Monitoring

    The prevention guide covers four approaches:

    • Add Logging to Your Code
    • Collect Logs from the Rest of Your Stack
    • Aggregate and Store Logs Securely
    • Monitor Your Application
  • Logging and Monitoring quiz

    Three questions. Passing marks the lesson complete.

Sources

  • Insecure Design

    Security begins before you start writing code.

  • Information Leakage

    Revealing system information helps an attacker learn about your tech stack.

  • Denial of Service Attacks

    Sometimes attackers don't need to hack your website, they just want to make it unavailable to others.

  • User Enumeration

    Leaking username information on your site makes things much easier for hackers.