Skip to main content

Management / Logging / Threats / DEV

Log Schema or Format Drift

CCC.Logging.TH03

Changes in source application or cloud service log formats, schemas, or underlying data structures lead to parsing failures, incomplete log ingestion, or render existing queries and dashboards ineffective, hindering comprehensive analysis.

Related Capabilities

IDTitleDescription
CCC.Logging.CP05Custom Log Format SupportAbility to ingest custom log formats or data from on-premises systems or other cloud environments via agents.
CCC.Logging.CP06Log Filtering & TransformationAbility to to filter, normalise, and transform raw log data at ingestion to optimise storage and enhance usability.
CCC.Logging.CP11Log-based MetricsAbility to extract quantitative metrics from log data for performance monitoring and operational analysis.

External Mappings

FrameworkIDRemarks
MITRE-ATT&CKT1562Impair Defenses (indirectly, by breaking detections)
MITRE-ATT&CKT1562.008Impair Defenses: Disable Cloud Logs (can lead to effective disablement)