Skip to content
ControlVerdict
AU.L2-3.3.1addresses
AU.L2-3.3.1System Auditing
Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.
  • [a]

    audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified;
  • [b]

    the content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined;
  • [c]

    audit records are created (generated);
  • [d]

    audit records, once created, contain the defined content;
  • [e]

    retention requirements for audit records are defined; and
  • [f]

    audit records are retained as defined.

View full control

Central SIEM with required event catalog and 90-day hot retention

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. Only 2 verdicts so far.Last verdict Aug 2, 2026

Implementation

AO coverage. Addresses all create/retain audit-record objectives for this practice.

Event catalog (minimum). Successful/failed authentication (IdP + local), privileged role activation, changes to security groups that gate CUI, MFA method registration/removal, endpoint malware detections from Falcon, firewall / Conditional Access policy edits, and admin configuration changes on the IdP and Sentinel itself.

Collection. Entra audit logs stream continuously to Sentinel. Endpoints forward security telemetry via Falcon and the Azure Monitor Agent where needed. Linux jump hosts use journald → forwarder with immutable local spool if Sentinel is unreachable.

Time. All collectors NTP-synced; Sentinel normalizes to UTC.

Retention. Hot searchable retention ≥ 90 days for the catalog above; cold archive per contract (often 1 year). Deletion of Sentinel retention settings is itself logged and alerted.

Maintenance. Weekly “silent source” check: each expected source must have sent events in the last 24h or a ticket opens. Quarterly review that new CUI apps were added to the catalog.

Accepted gap. One SaaS CAD tool offers only 30 days of native audit export. A daily pull job archives those events into Sentinel; failure of the pull alerts on-call.

What the evidence looks like

  • Event catalog mapped to systems
  • Sentinel data-connector / Falcon agent inventory
  • Retention settings screenshot/export
  • Sample queries proving each event type is present
  • Silent-source alert ticket history

Environment

Cloud-heavy OSC; mix of Windows endpoints and a small Linux jump tier.

Tools

2 ratings on this revision

  • AlignedControlVerdict Consultant@cv-consultantConsultantAug 2, 2026

    Across the finish line

    Rationale document plus collection config plus retention is a solid package for a small SIEM.

  • BorderlineControlVerdict Assessor@cv-assessorAug 2, 2026

    Across the finish line

    Event catalog with rationale is the right idea.

    Gaps

    Need stronger proof that the listed events are actually collected end-to-end, not just documented as intent.

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.