skip to content

Telemetry & Log Sources

Where a SOC's records come from - Sysmon and Windows event channels, auditd, NetFlow, DNS, mail and control-plane trails - and what each can prove. Interviewers open with 'which logs would you check'.

on this pageshow

explore

questions

page 1 of 2

Why does a SOC audit its own analysts' SIEM search queries?

level: juniorimportance: must knowfreq 58%

answer

  1. The search bar is a privilege
  2. Analysts are a monitored population too
  3. Who searched which identifier, when
  4. The case reference supplies the purpose
  5. Stored where analysts cannot edit it

basics

~20 s

Reading employee telemetry is itself a privileged act. The query audit records who searched which identifier, when, and under which case reference, so analyst misuse is detectable and the SOC's own access to people's data is evidenced.

solid answer

~40 s

A SOC's search bar reaches mailboxes, endpoints, sign-ins and web history for named people, so running a query exercises privilege the way an admin login does. The query audit is the control over it: for every search it records the account, the timestamp, the index, the query text, the time range and the case reference the search ran under. That buys deterrence and detection of misuse — the analyst looking up an ex-partner, a colleague or an executive is a real, recurring pattern; defensibility, so an employee or representative asking who read their data gets evidence; and protection for the analyst, since a query tied to an open case shows they were working. The audit must live where SOC staff cannot edit it, and be reviewed outside the SOC's reporting line.

code

json · 10 lines
json
{
  "event": "search.executed",
  "time": "2026-03-11T02:41:07Z",
  "actor": "analyst.jdoe",
  "index": "mail_audit",
  "query": "recipient:[email protected] OR sender:[email protected]",
  "time_range": "-90d..now",
  "case_ref": null,
  "results_returned": 412
}

go deeper

for a junior

Be ready to say plainly that running a search over a named employee is a privileged act, and that your own queries are recorded with your account, the identifiers and the case you ran them under.

for a middle

Explain the fields that make the record useful — actor, index, query, time range, case reference — and why a null case reference is the pattern that gets reviewed rather than an automatic finding.

for a senior

Show the failure modes: shared accounts, unaudited export and direct-query paths, and an audit index the SOC itself administers. Say who reviews it and on what cadence.

for a principal

Own the argument that the SOC's access power needs the same accountability it demands of admins, and be able to defend the SOC's record of access to an employee representative or an auditor.

## The SOC as a subject, not only an operator Almost everything else on this topic treats the SOC as the party doing the watching. The query audit inverts that: the analysts themselves become a monitored population, and their searches become a log source like any other. The reason is simply the reach of the tooling. A tier-1 analyst with a normal console can typically pull a named person's mailbox activity, their endpoint process telemetry, their sign-in history, their proxy or DNS records and their file access. That is a more intimate view of an employee's day than their own manager has, it is available in seconds, and it leaves no trace on the subject's side. An organisation that hands out that capability without a record of how it is used has created an unaudited surveillance power. ## What the record contains A usable query-audit entry captures, at minimum: | Field | Why it matters | | --- | --- | | Actor account | Who ran it — and it must be a named human account, not a shared service account | | Timestamp | When, including out-of-hours patterns | | Index or source | Mail audit, endpoint telemetry, sign-in logs, HR data | | Query text | Which identifiers were named | | Time range | A 6-hour window versus 90 days is a completely different intrusion into someone's life | | Case reference | The stated purpose — the field that turns a search into an authorised act | | Result count | Whether anything was returned | The case reference is the important one. Nothing in the query itself supplies a purpose; the link to an open, approved case does. A search with a null case reference is not automatically misconduct, but it is the pattern worth asking about. ## What the record proves, and what it does not A query-audit entry proves that **an account submitted that query at that time**. It does not prove a human was at the keyboard, that the analyst read or understood the results, that the results were exported, or that the purpose was legitimate. It equally does not prove the reverse: an analyst who ran no query may still have seen the data on a dashboard, in an alert payload, or in a screenshot a colleague pasted into a chat. That direction matters when the audit is used as evidence in a disciplinary case. "The account ran a 90-day mailbox search for a named colleague with no case reference" is a defensible, factual claim. "The analyst read their colleague's email" is a stronger claim that the record alone does not carry. ## Detections written over it Because it is just another log source, you can write detections on it. Common ones: - a search naming the analyst's own identifiers (self-lookup); - searches for identifiers with no linked open case; - lookups of a watchlist of executives, board members, HR staff or high-profile employees; - a sudden rise in the number of distinct subjects one analyst queried in a day; - unusually broad time ranges on person-scoped searches; - bulk exports, which frequently escape the audit entirely. These are low-volume and high-consequence, so they are usually reviewed by a person rather than paged. ## The failure modes that make the control fake 1. **Shared accounts.** If four analysts share one console login, the audit names nobody. 2. **Unaudited paths.** An analyst who queries the underlying data store directly, opens a notebook against the raw index, or pulls a CSV export may bypass the audited interface completely. Every read path needs to be audited, or the audited one becomes optional. 3. **The subject administers the audit.** If SOC staff can delete or edit the query-audit index, it cannot be used against them. Ship it to an append-only store outside their administrative control. 4. **Nobody reviews it.** An audit no one reads deters only people who believe someone reads it. Assign the review to a function outside the SOC's line — internal audit, privacy, or compliance. 5. **No case reference field.** Without a purpose binding, every entry looks equally justified and the audit answers no question. ## Why interviewers ask it It is a fast test of whether a candidate sees the SOC as accountable rather than merely trusted. Someone who answers "so we can catch analysts snooping" has half of it; the stronger answer adds that it makes the organisation's *own* access to employee data evidenced, which is what you need when an employee, an employee representative or an auditor asks the question.

  • What detections would you write over the analyst query audit?
    Self-lookups where an analyst names their own identifiers; searches with no linked open case reference; queries naming executives, HR staff or board members from a watchlist; a jump in distinct subjects queried per analyst per day; unusually wide time ranges on a person-scoped search; and bulk exports. Volumes are low and consequences are personal, so these go to a human reviewer outside the SOC line rather than to the pager.
  • The query audit shows an analyst searched a colleague's mailbox with no case reference. What does that record establish?
    That the analyst's account submitted that query, against that index, over that time range, at that time, with no case linked. It does not establish that a human was at the keyboard, that the results were read or exported, or that there was no legitimate reason. It is enough to open a question, and it is the factual claim you can defend; anything stronger needs corroboration such as endpoint activity, exports or an interview.
  • Where should the query-audit log live, and who reads it?
    In a store that SOC analysts and SOC platform admins cannot alter or delete — append-only, ideally shipped outside the team's administrative control — because otherwise the subject of a future case administers their own evidence. Review belongs to a function outside the SOC's reporting line, typically internal audit, privacy or compliance, on a defined cadence rather than only when someone complains.

A hospital logs which staff opened which patient record, not because clinicians are suspected, but because opening a record is an act with a subject who deserves an answer about who read it.

saying these in an interview costs you the question

  • Assumes analysts are trusted so no audit is needed
  • Treats a query record as proof the analyst read the data
  • Stores the query audit in an index analysts administer
  • Omits the case reference, so no search has a stated purpose
  • Ignores export and direct-database read paths that bypass the audit

context

open as a page

With 90-day SIEM retention, a partner reports an intrusion seven months old — what can you no longer answer?

level: juniorimportance: must knowfreq 62%

basics

~20 s

Anything about months four to seven. When access began, how it was obtained, and what it touched back then are unsearchable. You can describe only the last 90 days, and an empty result outside the window proves nothing.

open as a page

What is the difference between a log record's event time and its ingest time in a SIEM?

level: juniorimportance: must knowfreq 70%

basics

~20 s

Event time is when the source says the activity happened; ingest time is when your collector received the record. Event time answers when it happened, ingest time answers the earliest moment the SOC could have known about it.

open as a page

In SOC log-source coverage, what is the difference between an enrolled host and a reporting host?

level: juniorimportance: must knowfreq 72%

basics

~20 s

Enrolled means a host is registered in the collection console, which is a configuration fact. Reporting means its events actually arrived in the SIEM inside a recent window, which is an observed fact. Count coverage from arrivals.

open as a page

Why normalise vendor logs onto a shared schema like OCSF or ECS?

level: juniorimportance: must knowfreq 62%

basics

~10 s

A shared schema gives every product one field name for the same idea, so a single detection, search or pivot works across all feeds instead of being rewritten once per vendor dialect.

open as a page

Windows Security Event ID 1102 fired on a compromised workstation — does that mean the logs for that period are gone?

level: juniorimportance: must knowfreq 72%

basics

~20 s

Event ID 1102 records that the Windows Security log was cleared, and is written after the clear itself. Anything already forwarded to the collector survives there, so the cleared window is usually still readable centrally.

open as a page

What does a cloud control-plane audit entry prove about an admin action, and what does it not?

level: juniorimportance: must knowfreq 72%

basics

~20 s

A control-plane audit entry proves an authenticated API request reached the platform, which identity presented credentials, from where, and whether the platform allowed it. It proves nothing about who was at the keyboard or what happened inside the workload.

open as a page

What does a Windows Security 4624 record with logon type 3 actually prove?

level: juniorimportance: must knowfreq 78%

basics

~10 s

It proves a credential was accepted for that account on that machine, and nothing about who supplied it. Logon type 3 adds that the logon came over the network rather than at the keyboard.

open as a page

In a SaaS mail tenant, what does a message-trace record prove about an email, and what does it not?

level: juniorimportance: must knowfreq 72%

basics

~20 s

A message trace is the mail platform's delivery ledger: sender, recipients, time, subject and disposition such as delivered, quarantined or failed. It proves the platform handled the message; it carries no body and shows nothing about whether a human read it.

open as a page

What does a NetFlow or IPFIX flow record prove about a connection, and what can it never show?

level: juniorimportance: must knowfreq 74%

basics

~20 s

A flow record proves that two addresses and ports exchanged a counted number of bytes and packets during a time window, as seen at one observation point. It carries no payload, so it never shows what was sent.

open as a page

What does a Sysmon Event ID 1 record contain that Windows Security 4688 does not by default?

level: juniorimportance: must knowfreq 68%

basics

~20 s

Sysmon Event ID 1 adds file hashes, a unique ProcessGuid, and the parent's image path and command line. Windows Security 4688 also records process creation, but carries no hashes and includes the command line only when audit policy enables it.

open as a page

An inbox rule files finance replies into a rarely-opened folder and forwards them out — why is the rule record itself your evidence?

level: middleimportance: must knowfreq 66%

basics

~20 s

Rule creation is an intruder action the platform recorded with an actor, a timestamp, a client address and the rule's parameters. It is datable and attributable, it shows intent to blind the owner, and it outlives a password reset.

open as a page

An identity-provider sign-in record shows MFA satisfied by a claim in the token. What does that assert?

level: seniorimportance: must knowfreq 57%

basics

~10 s

That the credential presented already carried a multi-factor claim from an earlier authentication; nobody was challenged at this sign-in. It evidences a token being refreshed or replayed, not a person authenticating now.

open as a page

A partner reports your NAT address hitting their sinkhole at 02:14 — how do you name the internal host?

level: seniorimportance: must knowfreq 57%

basics

~20 s

A public address and a timestamp identify a NAT gateway, not a host. Reverse it with the firewall's NAT translation log matched on the public source port, then DHCP leases to name the machine and identity logs to name the account.

open as a page

What does two-person approval add before opening a named employee's mailbox telemetry?

level: middleimportance: should knowfreq 47%

basics

~20 s

It splits wanting the data from authorising it: the analyst who requests access cannot grant it. The recorded approval also bounds the access — named subject, named sources, a date range, an expiry — turning an open capability into a specific grant.

open as a page

How do you set a log-retention horizon from a right-skewed distribution of observed intrusion dwell times?

level: middleimportance: should knowfreq 45%

basics

~10 s

Take a high percentile of dwell, never the median, then add the lag from discovery to first search plus the weeks the case runs. Treat your own dwell data as truncated at current retention.

open as a page

A VPN appliance's syslog places a session seven minutes before the sign-in that authorised it - why?

level: middleimportance: should knowfreq 52%

basics

~20 s

Almost certainly the appliance's clock, not the order of events. BSD-style syslog carries no timezone and no year, so a drifting or locally set clock is copied straight into the SIEM and can place an effect before its cause.

open as a page

Your collector shows a syslog source as healthy while no security events arrive — how is that possible?

level: middleimportance: should knowfreq 56%

basics

~20 s

Health and security data travel as separate channels. The agent's heartbeat keeps flowing while the security channel stops: the audit source is off, the tailed file rotated, or a parser drops the records. Health proves the agent lives, not delivery.

open as a page

A CEF mapping caps process command lines at 1023 characters — what does that destroy?

level: middleimportance: should knowfreq 48%

basics

~20 s

Everything past the cap is gone with no error, so executions that differ only in their tail arrive as byte-identical strings. They dedupe into one repetitive-looking event, and the bytes that would have distinguished them never left the mapper.

open as a page

An authenticated vulnerability scan floods a host's Security channel — how can that erase the intrusion window before the forwarder ships it?

level: middleimportance: should knowfreq 48%

basics

~10 s

A Windows event channel is a fixed-size file that overwrites its oldest records first. If the write rate beats the forwarder's drain rate, records are destroyed before being shipped, silently and with no marker.

open as a page

At Metadata audit level, a Kubernetes entry shows a create on pods/exec into production — what can you establish?

level: middleimportance: should knowfreq 52%

basics

~20 s

That an authenticated identity was allowed to open an exec session into a named pod and container, when and from where, plus the command argv in the request URI. Nothing typed inside the session is audited.

open as a page

A host logs hundreds of Windows Security 4625 failures overnight; what does the sub-status field let you conclude?

level: middleimportance: should knowfreq 61%

basics

~10 s

The sub-status names why each logon failed. 0xC000006A is a real account with a wrong password, 0xC0000064 is an account that does not exist, 0xC0000234 is a locked-out account. Those are three different stories.

open as a page

A domain controller logs 40 Kerberos 4769 service-ticket requests from one host, all encryption type 0x17. What do you conclude?

level: middleimportance: should knowfreq 47%

basics

~20 s

One account asked the KDC for tickets to 40 services in RC4 (0x17) — the shape of kerberoasting, which harvests tickets to crack offline. The record proves tickets were issued, not that any service was accessed.

open as a page

Your border exports 1-in-1000 sampled NetFlow — why might a short DNS-tunnel session leave no record?

level: middleimportance: should knowfreq 50%

basics

~20 s

Packet sampling exports a flow only if one of its packets was picked. At 1 in 1000, a session of a few dozen packets has roughly a 2 percent chance of appearing, so short sessions vanish and their absence proves nothing.

open as a page

In a Sysmon Event ID 1 record, how much does the ParentImage field actually prove?

level: middleimportance: should knowfreq 44%

basics

~20 s

Only that the operating system regarded that process as the creator. Windows lets a caller nominate an arbitrary parent at creation, so the record can name a process that never launched anything: faithful log, wrong notion.

open as a page

A works-council agreement bars per-employee endpoint telemetry outside an approved case. How do you run a hunt that needs it?

level: seniorimportance: should knowfreq 36%

basics

~20 s

Reshape the hunt to data you may hold: host-level or pseudonymised identifiers, a narrow field set, a short window, with names revealed only if a hit justifies approval. If it cannot be reduced, use the agreed break-glass or record an accepted blind spot.

open as a page

Your cold log archive rehydrates in nine hours and a live intrusion case needs eight-month-old sign-in logs — what do you do?

level: seniorimportance: should knowfreq 40%

basics

~20 s

Start the narrowest possible restore immediately and keep working in parallel — nine hours only costs you the case if it is serialised. Then decide whether any containment action today actually depends on the restored data.

open as a page

A laptop reconnects and flushes six hours of buffered EDR events - what does that do to your hunt?

level: seniorimportance: should knowfreq 40%

basics

~20 s

It invalidates the negative result. The sweep covered the hours those records describe, but the records had not arrived yet, so nothing found meant nothing had arrived. Re-run the sweep over what has been received since.

open as a page

A site's syslog volume fell to zero eleven days ago and nobody noticed — tampering or a benign change?

level: seniorimportance: should knowfreq 48%

basics

~20 s

Treat it as unexplained rather than calm. Pin the cut to the minute, scope what stopped, demand a change record whose timestamp matches, corroborate from a surface off that path. Those eleven days are a blind period.

open as a page

After a merger, two proxy feeds share one normalised action field with different meanings — what breaks?

level: seniorimportance: should knowfreq 38%

basics

~10 s

Every rule, dashboard and verdict reading that field silently averages two vocabularies. One feed's deny means the request was blocked; the inherited feed's deny means a monitor-mode policy matched and the traffic still completed.

open as a page

showing 1–30 of 45