AU.L2-3.3.1System Auditing
Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.
[a]
audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified;[b]
the content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined;[c]
audit records are created (generated);[d]
audit records, once created, contain the defined content;[e]
retention requirements for audit records are defined; and[f]
audit records are retained as defined.
Central SIEM with required event catalog and 90-day hot retention
Implementation
AO coverage. Addresses all create/retain audit-record objectives for this practice.
Event catalog (minimum). Successful/failed authentication (IdP + local), privileged role activation, changes to security groups that gate CUI, MFA method registration/removal, endpoint malware detections from Falcon, firewall / Conditional Access policy edits, and admin configuration changes on the IdP and Sentinel itself.
Collection. Entra audit logs stream continuously to Sentinel. Endpoints forward security telemetry via Falcon and the Azure Monitor Agent where needed. Linux jump hosts use journald → forwarder with immutable local spool if Sentinel is unreachable.
Time. All collectors NTP-synced; Sentinel normalizes to UTC.
Retention. Hot searchable retention ≥ 90 days for the catalog above; cold archive per contract (often 1 year). Deletion of Sentinel retention settings is itself logged and alerted.
Maintenance. Weekly “silent source” check: each expected source must have sent events in the last 24h or a ticket opens. Quarterly review that new CUI apps were added to the catalog.
Accepted gap. One SaaS CAD tool offers only 30 days of native audit export. A daily pull job archives those events into Sentinel; failure of the pull alerts on-call.
What the evidence looks like
- Event catalog mapped to systems
- Sentinel data-connector / Falcon agent inventory
- Retention settings screenshot/export
- Sample queries proving each event type is present
- Silent-source alert ticket history
Environment
Tools
2 ratings on this revision
Across the finish line
Rationale document plus collection config plus retention is a solid package for a small SIEM.
Across the finish line
Event catalog with rationale is the right idea.
Gaps
Need stronger proof that the listed events are actually collected end-to-end, not just documented as intent.
Was this example useful?
Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.
Discussion(0)
No discussion on this example yet
Verdicts capture a conclusion. Use a thread when the interesting part is the argument.
Sign in to start a thread.