What’s in Your Logs? - Expert Edition
Wednesday 10 February 2027, 11:30–12:30
Speakers
- Bert-Jan Pals
About this session
Threat hunters, Detection Engineers, SOC/IR analysts and other security specialists all depend on logs. Yet one of the biggest challenges in remains surprisingly fundamental: Do you actually know what is in your logs? Most security teams know which data sources they have onboarded. They know the tables, schemas, and products. But knowing that a log source exists is not the same as understanding the full security value hidden within it. This Level 500 Black Belt session goes beyond the traditional discussion of log sources and telemetry. We will explore using demo's how to systematically discover, validate, classify, and operationalize the data available in your environment. After this session, attendees will have: - A repeatable methodology for exploring unfamiliar log sources. - Techniques for discovering security-relevant telemetry hidden in existing data. - Azure native automation for log content and schema discovery. - Practical ways to connect log discovery with threat hunting and detection engineering. Audience: Experienced threat hunters, detection engineers, SOC analysts, incident responders, security architects, automation specialists and everyone who wants to get more value out of their logs