Skip to main content

6. Required Telemetry

Required telemetry

No detection programme compensates for missing telemetry. The analytics in §4 require the following log sources to be collected, forwarded to SIEM, and retained for the minimum periods shown.

danger

The HR system integration is the most underinvested integration in most programmes and the one with the greatest leverage over detection quality.


Identity and Access (Foundation)

SourceRequired FieldsMinimum Retention
IdP sign-in logs (Entra ID, Okta, ADFS, Ping)User UPN, device ID, IP, ASN, MFA method, session ID, conditional access result1 year
Active Directory security audit events4624, 4625, 4720, 4728, 4732, 4756, 4740, 4767, 1102 from all domain controllers1 year
HR system integrationCurrent employment status, departure date, role, department, manager — fed to SIEM within hours of changeOngoing

Endpoint

SourceMinimum EventsNotes
Sysmon (maintained configuration)1 (process create + cmdline), 2 (file creation time change), 3 (network connection), 7 (image loaded), 11 (file create), 12/13 (registry create/modify), 17 (named pipe), 22 (DNS query), 23 (file delete — requires Sysmon v7.01+)Deploy with community-maintained config (SwiftOnSecurity or Florian Roth as baseline)
Windows process creationEvent 4688 + "Include command line in process creation events" policyRequired for all endpoint detection methods
DLP endpoint agentRemovable media events, sensitive file-path access, print operationsRequired for §4.1 USB and §4.2 print

Data and SaaS

SourceNotesRetention
Microsoft 365 Unified Audit LogAll available operations. MailItemsAccessed requires Microsoft Purview Audit (Premium).1 year (standard tier)
File server object access (Event 4663)SACLs on sensitive directories only — applying SACLs to all files generates unmanageable volume1 year
CASB or web proxyPersonal cloud storage and SaaS upload visibility; HTTPS inspection required for URL-level fidelity90 days minimum
SaaS platform audit logsGitHub, GitLab, Slack, Jira, Confluence, Salesforce, Workday, ServiceNow — availability and depth vary by licence tierPer-platform

Cloud Infrastructure

SourceScope
AWS CloudTrailAll regions, all management events; S3 data events on sensitive buckets; Lambda invocation logging on production functions
Azure Activity LogMicrosoft Defender for Cloud alerts
GCP Cloud Audit LogsAdmin Activity; Data Access for sensitive projects

Network

SourceNotes
Full QNAME DNS resolver logsWindows DNS debug logging or Zeek dns.log on recursive resolvers; standard Windows Event logs do not contain full query names
Web proxy logsFull URI, user-identity attribution (not just IP), and content-type

HR Integration (Critical)

DataFeed Latency Requirement
Departure datesAt least 24 hours before departure date where feasible; within hours of same-day resignation
Leave calendarDaily sync minimum
Role change events (transfers, promotions, department moves)Within hours of change
Disciplinary and performance flagsRequire HR/Legal approval framework before integration with security monitoring in most jurisdictions

Retention Guidance

Log CategoryMinimum RetentionRationale
Identity / IdP1 yearCover 86-day average dwell time + investigation window
Cloud control-plane1 yearCover post-termination access discovery
SaaS audit1 yearCover departure-window investigation
Endpoint (Sysmon)90 days minimumHigh volume; balance cost vs investigation window
Long-retention (identity, control-plane, network device)3 yearsDesjardins ran 26 months; Zheng ran over a decade