Security logs are meaningful elements which can show relevant information about end-user activities to security analyst under SOC(Security Operation Center) Logs are three types which will be triggered according to your activities performed in your system. Logs which footprinting the process of kernel boot, driver updates or failure, windows update and more interesting things will be logged into system log category. People, process, and technology will be a triangle for security operations. Logs and packets depend on logs and packets to have a better view above 90 % of them are working with logs rather than packets.”]
Source: https://gbhackers.com/siem-for-better-visibility-for-an-analyst-to-handle-an-incident/