The end goal is having an intelligent understanding of the events within the organization. To reach this goal, one of the things we must do is extract meaningful information from logs. The first step is defining the types of events we want to capture. These events should relate to the risks requiring response. In the beginning, well focus on data that is easily logged, correlated, and acted on. After those event types are well-implemented, we move to event types that are high volume, less accurate, or require more correlation.”]

