Monitoring & Detection
Review Useful Logs and Security Alerts
Start with existing identity, email, endpoint, and backup alerts. A paid SIEM is not a prerequisite.
Content review: 2026-09-22 · Estimated effort: High
Priority and effort are editorial starting points, not calculated risk or mandatory deadlines. Adapt to business impact, vendor instructions, available licenses, and applicable obligations. Test changes before broad rollout.
Before you start
Before starting: name an alert owner and backup contact. Check log availability, licensing, retention limits, and privacy obligations in your existing services.
Put it into practice
- Enable available audit logs for important sign-ins and administrator actions. Identify where endpoint, email, and backup alerts appear.
- Start with a few actionable alerts and a response checklist. Document review times and what happens outside normal hours; do not imply 24/7 coverage unless it exists.
- Choose retention based on investigation needs, applicable obligations, cost, and privacy. There is no universal hot/cold retention period for every small business.
- Restrict log access, check timestamps, and avoid logging passwords or unnecessary sensitive data. Consider centralized logging or a SIEM only when investigation needs justify its operating effort.
- Verify: generate a safe test event, find it in the log, confirm alert delivery, and ask the owner to follow the response instructions.
Make a start
Tools and templates
Start with what you already have. “Included” means part of an existing eligible product or subscription, not a free standalone service. Options reviewed 2026-09-22; check current vendor terms before choosing.
Start without another software subscription
Start with available service logs and built-in Windows event logs. Use the free worksheet to assign reviewers and rehearse responses.
Where this stops: Local Windows logs do not replace Microsoft 365 audit records. Manual review is not continuous detection, long-term central retention or a staffed response service.
See the official sources and eligibility details below. Free software can still require equipment, storage and staff time.
Windows event logs and wevtutil
Built-in Windows capability; no separate monitoring subscription
An authorized administrator can use Event Viewer or the documented read/query and export operations to inspect a benign test event. Give the relevant logs a reviewer and an escalation route.
Limits: Only events actually collected are available. Local logs can roll over and do not supply cloud-service audit coverage, automatic alert triage or continuous monitoring. Do not clear logs while testing.
Your information: Logs and exports can contain usernames, device details and activity. Restrict access and choose approved storage and retention for exports.
Official instructions: Windows event logs and wevtutil ↗Microsoft Purview Audit
Audit Standard is included in eligible subscriptions; verify your plan
Use the Audit solution with an authorized audit role to locate an approved test event. Assign someone to review the relevant records and handle alerts.
Limits: Event availability, retention and advanced features depend on licensing. Searching logs is not continuous monitoring or a staffed response service.
Your information: Audit records contain user activity and identifiers in Microsoft services. Restrict access and exports; define retention before collecting extra logs.
Official instructions: Microsoft Purview Audit ↗Download a working template
Free to download and adapt for your team. Open CSV files in Microsoft Excel using your existing Office license; Markdown files open in a text editor such as Notepad. Save an Excel Workbook (.xlsx) copy if you add formatting. These are manual worksheets, with no macros, scoring or automatic verification.
- Log and alert review record (CSV) ↓
Give each log or alert a reviewer, response route and tested delivery path. Record a restricted evidence reference rather than copying raw logs.
Fictional worked example
Illustration only. This is not a customer story, lab result, or evidence that your environment is protected. Replace the example entries and record your own observations.
A team needs to know who checks identity events and who responds when the usual reviewer is away.
Use the Log and alert review record template.
What to enter before testing
- Log or alert source
- EXAMPLE: available identity sign-in log
- Primary reviewer role
- IT owner
- Backup reviewer role
- Approved alternate
- Delivery and event visibility result
- Not tested
How to verify
Generate a benign authorized event supported by the chosen service, then confirm the reviewer can find it with the expected identity and time. If an alert is configured, test delivery and rehearse the handoff separately. Record the service’s actual access and retention limits.
If the result is unexpected
If the event or notification is missing, investigate collection, licensing, scope and delivery. An event appearing in a log does not mean an alert was sent or acted on. Keep the review gap open until its intended response path is demonstrated.
Save completed worksheets privately. They can describe security gaps, systems and people. Do not include passwords, recovery keys or confidential message content. This site does not receive your edits; a cloud editor or synced folder may send them to its provider.
Sources and review approach
Original small-team guidance with selected NIST CSF 2.0 alignments, not an official crosswalk or a complete framework implementation. These instructions are a starting point, not a claim of testing in your environment.
- NIST CSF 2.0: PR.PS-04: log generation
- NIST CSF 2.0: DE.CM: selected monitoring outcomes, not full coverage