
THREAT‑WATCH
Glossary
Log Management
The practice of collecting, storing, and analyzing the activity records ('logs') generated by systems, applications, and network devices.
Logs record who did what, when, and from where, across every system in an environment, and are the raw material a SOC or SIEM correlates to detect threats and reconstruct what happened during an incident. NIS2 and ISO 27001 both expect adequate log retention specifically because logs are often the only evidence available during a post-incident investigation.