– OS, Applica2on, Firewalls, Switches, Routers, etc.. – Look for things like bad login aUempts – Unusual requests, usage paUerns – Supports large number of files/formats (Apache, MySQL, Postgres, na2ve system logs) – Also supports analyzing output of processes (e.g. netstat, ifconfig, …) – Can be used in conjunc2on with WAFs, DAFs