Log Monitoring
Noun · Security & Infosec
Definitions
The continuous review of logs, either manually or through automated tooling, to detect suspicious activity, failures, or policy violations. Log monitoring is only effective when the right sources are collected and the resulting alerts are tuned to avoid overwhelming analysts.
In plain English: Watching logs continuously for suspicious or important events.
Example: "Log monitoring caught the unusual after-hours admin activity, but the team still lacked enough context to classify the incident immediately."