What Logs Do You Need for a Cyber Investigation? - System Force IT

What Logs Do You Need for a Cyber Investigation?

When you are trying to work out what an attacker did, logs are your memory. And the cruel irony of cyber incidents is that the moment you most need them is often the moment you discover they were never being kept, or rolled off three days ago. A log you did not record is a question you can never answer.

This guide sets out which logs a UK SME should keep, why, and for how long, so that if an incident happens you can actually investigate it rather than guess. It is a companion to our full cyber incident response plan guide.

Why logs matter so much

During an incident, logs let you answer the questions that decide everything else: how did the attacker get in, what did they touch, are they still here, and has any data left the building? Without logs you are working from assumption, which means over-reacting in some places and missing the real damage in others. Logs also matter afterwards, for your insurer, for any regulatory questions, and for learning the genuine lesson. Good logging turns “we think” into “we know”.

Many logs are kept for only a few days by default. If an incident is discovered two weeks after it started, and plenty are, the evidence has already gone. The single most valuable thing you can do before an incident is make sure the logs you would need are switched on and retained long enough to be useful.

The logs a UK SME should keep

Log source What it tells you
Identity and sign-in logs (Microsoft 365 / Entra ID) Who signed in, from where, when, and whether MFA was satisfied. The starting point for almost every investigation.
Microsoft 365 unified audit log Mailbox rule changes, forwarding, file access in SharePoint and OneDrive, admin actions, app consents. Essential for account-compromise cases.
Endpoint security / EDR What ran on a laptop or server, what was blocked, and signs of malware or attacker tools.
Firewall logs Traffic in and out, connections to suspicious addresses, and signs of data leaving the network.
DNS logs Which domains devices tried to reach, often the first sign of malware calling home.
VPN and remote access Who connected remotely, from where and when.
Server and application logs Activity on your key servers and line-of-business applications.
Cloud platform logs Activity in Azure, AWS or other cloud services you use.
Email security logs What was blocked, quarantined or delivered, useful for tracing a phishing campaign.
Backup platform logs Whether backups ran, and whether anyone tampered with them.

The Microsoft 365 gap to close today

The most common logging gap we find is Microsoft 365 audit logging. Discovering after a mailbox compromise that unified audit logging was switched off, or that your licence only retained logs for a short period, is a genuinely bad day, because the evidence of what the attacker did simply does not exist. Check now that unified audit logging is enabled and that your retention is long enough to be useful. This one check has saved more investigations than any tool.

How long to keep them

There is no single legal number that fits every business, so match retention to how long an incident might go unnoticed and how long you might need the evidence afterwards. As a practical rule of thumb for an SME, aim to keep the key logs, especially identity, Microsoft 365 audit, firewall and endpoint, for several months rather than days. Extending default retention is usually a small change with a large payoff. If a log rolls off after a week, it protects you only against incidents you spot within a week, and many are not.

Make sure you can actually reach them

Two practical points people forget. First, know where each log lives and who can get to it, before an incident, not during one. Second, protect the logs themselves. Attackers sometimes try to clear logs to cover their tracks, so where you can, send important logs somewhere the attacker cannot easily reach or delete. During an incident, export the logs you need early, before they roll off or are tampered with, and record what you exported in your evidence register.

Not sure what you are logging, or for how long?

We can review your logging across identity, Microsoft 365, endpoints, firewall and backups, tell you where the gaps are, and make sure that if an incident ever happens, you can actually investigate it.

Book a free IT and security review

Frequently asked questions

What logs do I need to investigate a cyber incident?

The core sources are identity and sign-in logs, the Microsoft 365 unified audit log, endpoint security, firewall, DNS, VPN, server and application logs, cloud platform logs, email security and your backup platform. Identity and Microsoft 365 audit logs are the starting point for most investigations at UK SMEs.

How long should I keep security logs?

There is no single legal figure, so match it to how long an incident might go unnoticed and how long you might need the evidence. For an SME, aim to keep key logs, especially identity, Microsoft 365 audit, firewall and endpoint, for several months rather than days, because many incidents are discovered weeks after they began.

Is Microsoft 365 audit logging on by default?

You should not assume so. A common and costly gap is discovering after a mailbox compromise that unified audit logging was off, or that your licence retained logs for only a short period. Check now that it is enabled and that retention is long enough to be useful.

Can attackers delete the logs?

They sometimes try, to cover their tracks. Where you can, send important logs somewhere the attacker cannot easily reach or delete, and during an incident export the logs you need early before they roll off or are tampered with.

Related reading: the full Cyber Incident Response Plan guide, how to preserve evidence after a cyber attack, and the free Cyber Incident Response Toolkit.

Practical guidance from System Force IT, UKAS ISO/IEC 27001:2022 certified, supporting UK businesses since 2006.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name