# Logs: start with the incident question

https://thiago.limaesilvatecnologia.com.br/en/artigos/logging-evidence/

Published: 2026-09-12

Event volume is not investigation capability.

Content produced with AI assistance for Thiago Silva’s website. Independent editorial analysis; it does not represent clients or employers.

Reading-path month: May 2026

Collection published on September 12, 2026. Months organize the reading path; they are not earlier publication dates.

A short architecture article. The technical reference supports the topic; hypothetical scenarios and assessment proposals are editorial analysis, not accounts of personal implementations.

## The architecture decision

Collecting many logs can create cost without explaining events. Observability architecture should start with investigation questions and accountability.

## Practical application

Editorial proposal: choose a critical operation and identify actor, resource, decision and outcome without unnecessary sensitive content. For a hypothetical export, identifying the requested dataset may matter more than copying its records into logs.

## How to verify

Reconstruct a synthetic journey using available telemetry alone. Record correlation gaps and evidence access. Include delivery failures and clock differences: investigation also depends on collection quality.

## Sources

- [OWASP — Logging Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html). Accessed: 2026-09-12.

[Profile: Thiago Silva | Cyber Architect](https://thiago.limaesilvatecnologia.com.br/en/perfil/)
