I4: Logs and Event Monitoring
Learn how defenders read authentication, system, application, network, web, and endpoint logs, connect related events, and explain evidence without jumping to conclusions.
Module Snapshot
Intermediate
Track
I4 of 17
Module
8
Lessons
25 questions
Module test
Evidence before conclusions
This module adds log sources, event fields, timestamp normalization, authentication review, pattern analysis, event correlation, and timeline documentation.
Main Question
How do defenders connect separate event records into an accurate and useful explanation?
Students will compare timestamps, users, devices, applications, services, addresses, actions, results, baselines, and approved changes before deciding what is confirmed, likely, uncertain, or unsupported.
Safety Boundary
Every log, event, account, address, domain, process, device, application, service, file, request, and organization in this module is fictional. Practice stays read-only, authorized, and limited to supplied training evidence.
Professional Workflow
Collect, Normalize, Contextualize, Correlate, and Document
Collect
Gather the fictional log sources, systems, users, time window, retention details, and review question.
Normalize
Align timestamps, time zones, device names, user identities, event fields, source labels, and formats.
Contextualize
Connect events with asset roles, user roles, expected schedules, applications, owners, and approved changes.
Correlate
Link related events using time, users, devices, processes, services, addresses, sessions, and request identifiers.
Document
Record confirmed facts, likely explanations, alternate explanations, evidence gaps, confidence, impact, and next action.
Learning Objectives
What Students Will Be Able to Do
Explain what logs are, why systems create them, and how defenders use them.
Interpret timestamps, event IDs, providers, users, devices, processes, actions, results, and severity labels.
Review fictional authentication, system, application, network, web, and endpoint logs.
Compare current activity with approved baselines and expected business context.
Build a simple multi-source event timeline while separating facts from conclusions and evidence gaps.
Document findings, confidence, limitations, ownership, escalation, and safe defensive next actions.
Module Path
Eight Intermediate Lessons
Each lesson includes professional hooks, fictional log evidence, safe defensive labs, scenario decisions, a scored quiz, a checklist, and a portfolio prompt.
I4.1
Lesson 1
What Logs Are and Why They Matter
Understand what logs record, why systems create them, and how defenders use logs for visibility, troubleshooting, monitoring, and response.
Defensive Lab
Classify fictional event records by source, purpose, useful fields, owner, and evidence limitation.
I4.2
Lesson 2
Timestamps, Event IDs, and Context
Read timestamps, event IDs, providers, severity labels, users, devices, actions, results, and correlation fields in context.
Defensive Lab
Normalize fictional records with different time zones, clock offsets, event formats, and collection delays.
I4.3
Lesson 3
Authentication Logs
Interpret fictional successful and failed sign-ins, lockouts, MFA activity, password resets, account changes, and session evidence.
Defensive Lab
Review an authentication sequence and distinguish expected password-reset activity from a pattern that needs escalation.
I4.4
Lesson 4
System and Application Logs
Connect operating-system, service, process, update, application, configuration, error, and recovery records.
Defensive Lab
Correlate a fictional application failure with service, permission, update, owner, and change evidence.
I4.5
Lesson 5
Network and Web Logs
Interpret firewall, DNS, proxy, web server, and connection records using source, destination, port, protocol, request, response, and ownership context.
Defensive Lab
Trace a fictional web request across DNS, firewall, proxy, and server logs without inspecting real traffic.
I4.6
Lesson 6
Normal vs Suspicious Patterns
Compare current activity with approved baselines and evaluate timing, frequency, source, destination, privilege, failure, and change context.
Defensive Lab
Classify fictional patterns as expected, unusual, suspicious, administrative, failed, or evidence-incomplete.
I4.7
Lesson 7
Building a Simple Event Timeline
Normalize and combine events from multiple sources into a clear chronological narrative with facts, conclusions, gaps, and confidence.
Defensive Lab
Build a twenty-event fictional timeline using authentication, system, application, network, endpoint, and change records.
I4.8
Lesson 8
Log Review Lab
Combine log sources, time normalization, event context, pattern analysis, correlation, and documentation into one defensive review.
Defensive Lab
Complete a multi-source fictional log review and create an evidence-based report with safe recommendations.
Fake Evidence Preview
How Intermediate Log Evidence Connects
10:02:14
Authentication
Two failed sign-ins from training-laptop-12
Shows unsuccessful attempts from an expected device but does not yet explain the cause.
10:02:18
Application
Mail client reports stored credential rejected
Adds application context suggesting an automatic retry with an old saved password.
10:03:07
Support
User confirms password was changed minutes earlier
Provides human and change context that may explain the failed attempts.
10:03:31
Authentication
Successful sign-in and approved MFA challenge
Shows the expected device completed the updated authentication sequence successfully.
Portfolio Outcome
Multi-Source Log Review Report
Students will build a fictional report containing source inventory, normalized timestamps, event fields, authentication, system, application, network, and web evidence, a correlated timeline, pattern analysis, confidence, limitations, and safe defensive recommendations.
Module Assessment
25-Question I4 Module Test
The test will cover log vocabulary, timestamps, event IDs, context, authentication, system, application, network, web, patterns, timelines, evidence limitations, and safe suspicious activity analysis. Answers stay hidden until submission.
Open Module Test