Log Analysis
Noun · Security & Infosec
Definitions
The examination of system, application, network, or cloud logs to identify anomalies, reconstruct events, or confirm suspicious behavior. Log analysis is central to both detection and forensic investigation because many attacker actions leave operational traces even when they try to hide them.
In plain English: Reviewing logs to find suspicious activity or understand what happened.
Example: "Log analysis showed the attacker authenticated successfully before deleting the exposed storage bucket."