Quick Forensics Analysis of Apache logs, (Fri, Mar 29th)
SANS Internet Storm Center, InfoCON: green 2024-03-29
Summary:
Sometimes, you&#;x26;#;xe2;&#;x26;#;x80;&#;x26;#;x99;ve to quickly investigate a webserver logs for potential malicious activity. If you&#;x26;#;39;re lucky, logs are already indexed in real-time in a log management solution and you can automatically launch some hunting queries. If that&#;x26;#;39;s not the case, you can download all logs on a local system or a cloud instance and index them manually. But it&#;x26;#;39;s not always the easiest/fastest way due to the amount of data to process.