

# HNSEC03-BP02 Set up central logging and analytics
<a name="hnsec03-bp02"></a>

 Establishing a centralized logging and analytics system is crucial for comprehensive visibility, security monitoring, and operational efficiency across both on-premises and cloud infrastructures. A central logging solution enables organizations to collect, store, analyze, and respond to events occurring throughout their distributed network environments. 

 **Desired outcome:** Achieve comprehensive visibility and efficient analysis across all networking environments for rapid detection and troubleshooting. 

 **Level of risk exposed if this best practice is not established:** High 

 **Benefits of establishing this best practice:** 
+  Centralizes monitoring and log management 
+  Streamlines threat detection and operational insights 
+  Supports compliance and audit requirements 
+  Simplifies troubleshooting across hybrid environments 

## Implementation guidance
<a name="implementation-guidance-16"></a>
+  Aggregate logs from on-premises and cloud environments to a centralized analytics platform. 
+  Implement dashboards and alerting for key performance and security events. 

## Resources
<a name="resources-15"></a>
+  [Centralized Logging with OpenSearch](https://aws.amazon.com/solutions/implementations/centralized-logging-with-opensearch/) 
+  [Amazon CloudWatch Logs](https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/WhatIsCloudWatchLogs.html) 
+  [Central Logging and Analytics in Hybrid Environments](https://d1.awsstatic.com/architecture-diagrams/ArchitectureDiagrams/central-logging-and-analytics-in-hybrid-environments.pdf) 