Log360 Resources Library

The complete documentation hub for all official product guides and best practices.

ManageEngine has been recognized in 2025 Gartner® Magic Quadrant™ for Security Information and Event Management.

Learn more
Categories
  • Getting started
  • User guides
  • Configuration guides
  • Best practices

Supported log & data sources

Provides a list of all compatible log sources and data types supported by Log360 for ingestion and monitoring.

 

Solution architecture

Illustrates Log360's deployment architecture, components, and data flow.

 

FAQs

Answers common questions about Log360 features, setup, troubleshooting, and licensing.

 

Log360 user guide

Complete user guide covering Log360 features, navigation, log management, alerts, and reporting.

 

Log360 UEBA user guide

User guide for Log360 UEBA covering behavior analytics setup, anomaly detection, and risk scoring.

 
pdf

Log360 admin guide

Admin guide covering Log360 administration settings, user roles, configurations, and management.

 
pdf

Log360 installation guide

Installation best practices for deploying Log360 securely and optimally in your environment.

 
pdf

SSL certificate guide

Step-by-step guide to configuring SSL certificates and enabling HTTPS for Log360.

 
pdf

Agent configuration guide

Guide to installing and configuring Log360 agents for log collection across devices.

 
pdf

Port configuration guide

Guide to configuring required ports on the server and remote hosts for Log360 communication.

 
pdf

Service account guide

Guide to creating and configuring service accounts required for Log360 log collection.

 
pdf

Log forensics best practices

Best practices for effective log forensics investigation and evidence preservation in Log360.

 
pdf

Ransomware prevention best practices

Best practices to detect, prevent, and respond to ransomware attacks using Log360.

 
  • Datasheet
  • Use case documents
  • Solution briefs
  • Industry briefs
  • Infographics
pdf
Zia for Log360 | AI-powered security operations

Zia for Log360 | AI-powered security operations

Covers Log360's AI capabilities, including conversational search, security agents, and MCP.

 
pdf
Log360 for Australian financial institutions

Log360 for Australian financial institutions

Explores ransomware defense, SQL threat detection, and compliance for Australian BFSI with Log360.

 
pdf
AI agents for your SOC

AI agents for your SOC

Details how Zia Agents in Log360 Cloud lets teams deploy prebuilt and custom AI agents for SOC automation.

 
pdf
Log360 Cloud MCP server

Log360 Cloud MCP server

Explains how the Log360 Cloud MCP Server lets analysts query logs, investigate alerts, and act from any AI client.

 
pdf
The rule-based, real-time correlation engine in Log360

The rule-based, real-time correlation engine in Log360

Provides an overview of Log360's rule-based real-time event correlation engine for automated threat detection.

 
pdf
Log360's integration with Endpoint Central

Log360's integration with Endpoint Central

Explores Log360's integration with Endpoint Central for unified endpoint visibility and monitoring.

 
pdf
Dark web monitoring in Log360

Dark web monitoring in Log360

Explains Log360's dark web monitoring capability to identify leaked credentials and sensitive data.

 
pdf
Smart Threshold in Log360

Smart Threshold in Log360

Highlights Log360's smart threshold feature for adaptive, ML-based anomaly detection.

 
pdf
Incident Workbench

Incident Workbench

Showcases Log360's Incident Workbench for streamlined security investigation and response.

 
pdf
Extend threat detection capabilities | Log360's MITRE ATT&CK

Extend threat detection capabilities | Log360's MITRE ATT&CK

Demonstrates how Log360's MITRE ATT&CK framework integration extends threat detection capabilities.

 
pdf
Unified SIEM solution with integrated DLP and CASB capabilities

Unified SIEM solution with integrated DLP and CASB capabilities

Features Log360 as a unified SIEM with integrated DLP and CASB for complete security coverage.

 
pdf
Security and Risk Posture Management | ManageEngine Log360

Security and Risk Posture Management | ManageEngine Log360

Explores Log360's security and risk posture management capabilities for enhanced risk visibility.

 
pdf
Attack detection capabilities | ManageEngine Log360

Attack detection capabilities | ManageEngine Log360

Explains Log360's attack detection capabilities to identify and respond to threats in real time.

 
pdf
Threat detection and response | ManageEngine Log360

Threat detection and response | ManageEngine Log360

Outlines Log360's threat detection and response capabilities for fast incident handling.

 
pdf
Securing cloud resources | ManageEngine Log360

Securing cloud resources | ManageEngine Log360

Explains how Log360 secures cloud resources across AWS, Azure, and GCP environments.

 
pdf
Data security with Log360

Data security with Log360

Highlights Log360's data security features including DLP, data classification, and access control.

 
pdf
Data collection in Log360

Data collection in Log360

Covers Log360's log data collection capabilities across on-premises and cloud environments.

 
pdf
Behavior analytics in Log360

Behavior analytics in Log360

Explores Log360's UEBA-powered behavior analytics for detecting insider threats and anomalies.

 
pdf
Rapid and accurate log forensics with Log360

Rapid and accurate log forensics with Log360

Demonstrates fast and accurate log forensics in Log360 for rapid threat investigation.

 
pdf
Log360 for compliance

Log360 for compliance

Explores Log360's compliance management capabilities across major regulatory frameworks.

 
pdf
Advanced threat analytics in ManageEngine Log360

Advanced threat analytics in ManageEngine Log360

Explains Log360's advanced threat analytics using AI and ML for proactive threat detection.

 
pdf
Incident detection and investigation in Log360

Incident detection and investigation in Log360

Explores Log360's incident detection and investigation capabilities for SOC efficiency.

 
pdf
Incident management in Log360

Incident management in Log360

Outlines Log360's end-to-end incident management workflow for response and resolution.

 
pdf
Account compromise detection using Log360

Account compromise detection using Log360

Explains how Log360 detects account compromise events through user behavior analysis.

 
pdf
Intrusion detection using Log360

Intrusion detection using Log360

Demonstrates how Log360 detects network intrusions via log correlation and threat intelligence.

 
pdf
Anomaly detection using Log360

Anomaly detection using Log360

Explores how Log360's UEBA identifies behavioral anomalies and unusual user activities.

 
pdf
Identifying and protecting patient health information with Log360

Identifying and protecting patient health information with Log360

Explains how Log360 identifies and protects patient health information (PHI) under HIPAA.

 
pdf
Using Log360 to discover sensitive data in the network

Using Log360 to discover sensitive data in the network

Shows how Log360 discovers and protects sensitive data scattered across the network.

 
pdf
Auditing change control with Log360

Auditing change control with Log360

Explains how Log360 audits and monitors change control activities across IT systems.

 
pdf
Spot privilege escalations using Log360

Spot privilege escalations using Log360

Explains how Log360 detects unauthorized privilege escalations by users or attackers.

 
pdf
Detect changes to sensitive data stored in databases using Log360

Detect changes to sensitive data stored in databases using Log360

Demonstrates how Log360 detects unauthorized changes to sensitive data in databases.

 
pdf
Securing resources and data on the cloud using Log360

Securing resources and data on the cloud using Log360

Explores how Log360 secures and monitors resources and data across cloud platforms.

 
pdf
Fraud detection and prevention using Log360

Fraud detection and prevention using Log360

Shows how Log360 detects and prevents fraudulent activities using behavioral analytics.

 
pdf
Monitor integrity of files and folders using Log360

Monitor integrity of files and folders using Log360

Explains how Log360 monitors file and folder integrity against unauthorized modifications.

 
pdf
Identifying a patient-zero machine using Log360

Identifying a patient-zero machine using Log360

Demonstrates how Log360 identifies the patient-zero machine in a malware outbreak.

 
pdf
Discovering and securing credit card information using Log360

Discovering and securing credit card information using Log360

Covers how Log360 discovers and protects credit card data for PCI DSS compliance.

 
pdf
Detecting APTs using MITRE ATT&CK TTPs | ManageEngine Log360

Detecting APTs using MITRE ATT&CK TTPs | ManageEngine Log360

Explains how Log360 detects advanced persistent threats using MITRE ATT&CK TTPs.

 
pdf
Safeguarding devices against ransomware using Log360

Safeguarding devices against ransomware using Log360

Explains how Log360 safeguards endpoints and servers against ransomware attacks.

 
pdf
GDPR solution book

GDPR solution book

Covers how Log360 helps organizations achieve and maintain GDPR compliance.

 
pdf
A solution book for IT security admins to meet GDPR requirements

A solution book for IT security admins to meet GDPR requirements

Guides IT security admins through meeting all GDPR requirements using Log360.

 
pdf
An IT admin's guide to POPIA

An IT admin's guide to POPIA

Helps IT admins understand and meet POPIA (South Africa's data protection law) requirements.

 
pdf
How Log360 helps Australian organizations with the Notifiable Data Breaches scheme

How Log360 helps Australian organizations with the Notifiable Data Breaches scheme

Explains how Log360 helps Australian organizations comply with the Notifiable Data Breaches scheme.

 
pdf
How SIEM helps businesses comply with PCI DSS

How SIEM helps businesses comply with PCI DSS

Demonstrates how SIEM helps organizations comply with PCI DSS payment card security standards.

 
pdf
Monitor privileged user activity using Log360

Monitor privileged user activity using Log360

Explains how Log360 monitors privileged user activities and detects insider threats.

 
pdf
Detect malicious traffic inflow using Log360

Detect malicious traffic inflow using Log360

Demonstrates how Log360 detects and alerts on malicious inbound network traffic.

 
pdf
Advanced threat detection for Australian financial institutions

Advanced threat detection for Australian financial institutions

Covers advanced threat detection use cases for Australian BFSI institutions including ransomware and SQL attacks.

 
pdf
SIEM in healthcare cybersecurity: Challenges, use cases, and compliance

SIEM in healthcare cybersecurity: Challenges, use cases, and compliance

Explores SIEM use cases, key benefits, and compliance guidance to ensure cybersecurity in healthcare.

 
pdf
Strengthening financial cyber resilience and fraud detection with Log360

Strengthening financial cyber resilience and fraud detection with Log360

Explores how Log360 helps BFSI organizations tackle fraud, ransomware, and insider threats.

 
pdf
Healthcare | Protect patient privacy using Log360

Healthcare | Protect patient privacy using Log360

Explores how Log360 protects patient privacy and supports healthcare compliance needs.

 
pdf
Educational Services | ManageEngine Log360

Educational Services | ManageEngine Log360

Highlights Log360's capabilities for securing educational institutions' IT environments.

 
pdf
Financial Services | ManageEngine Log360

Financial Services | ManageEngine Log360

Covers Log360's capabilities for financial sector security and compliance.

 
pdf
Translating AD weak spots

Translating AD weak spots

Highlights Active Directory weak spots attackers exploit and how to address them.

 
pdf
The Domino effect

The Domino effect

Illustrates the domino effect of undetected security incidents and cascading breaches.

 
pdf
Security policy recommendations for CISOs

Security policy recommendations for CISOs

Lists key security policy recommendations for CISOs to strengthen cyber defenses.

 
pdf
SIEM for banking security

SIEM for banking security

Explains how SIEM solutions protect banking and financial institutions from cyberthreats.

 
pdf
Best practices for data backups

Best practices for data backups

Emphasizes the importance of data protection and steps to secure sensitive information proactively.

 
pdf
10 cybersecurity tips to maintain peace at work

10 cybersecurity tips to maintain peace at work

Lists 10 practical cybersecurity tips to maintain security in workplace environments.

 
pdf
7 reasons why Log360 is your best friend in the cyber realm

7 reasons why Log360 is your best friend in the cyber realm

Presents 7 key reasons Log360 is a top SIEM tool for comprehensive cyber threat management.

 
pdf
Insider threat: The enemy is under your roof

Insider threat: The enemy is under your roof

Explains how to recognize, prevent, and mitigate insider threats from within the organization.

 
pdf
8 cyberhygine tips for remote work

8 cyberhygine tips for remote work

Provides 8 cybersecurity hygiene tips tailored for remote workers and distributed teams.

 
pdf
How not to fall prey to password attacks

How not to fall prey to password attacks

Covers common password attack types and how to defend against them effectively.

 
pdf
3 key updates in PCI DSS 4.0

3 key updates in PCI DSS 4.0

Summarizes the 3 major updates introduced in PCI DSS version 4.0.

 
pdf
14 measures for AD security

14 measures for AD security

Outlines 14 essential measures and best practices for securing Active Directory.

 
pdf
SOC analyst career roadmap – Skills, certifications & growth path

SOC analyst career roadmap – Skills, certifications & growth path

Maps the career roadmap for SOC analysts including skills, certifications, and growth paths.

 
pdf
The SOC incident response process

The SOC incident response process

Illustrates the step-by-step incident response process followed by SOC teams.

 
  • E-books
  • Whitepapers
pdf
Why detection alone isn't enough, and how modern SOCs close the gap

Why detection alone isn't enough, and how modern SOCs close the gap

Shows how Log360 unifies threat detection, AI-powered investigation, and automated response.

 
pdf
Getting the best out of your SIEM

Getting the best out of your SIEM

Explores strategies and tips for maximizing the effectiveness of your SIEM deployment.

 
pdf
Encryption standards of Log360 modules

Encryption standards of Log360 modules

Explains encryption standards used across Log360 modules to protect data at rest and in transit.

 
pdf
SIEM evaluator's guide

SIEM evaluator's guide

A guide to help security teams evaluate and shortlist the right SIEM solution for their needs.

 
pdf
The CISO's compass: Strategic responses to cyber breaches

The CISO's compass: Strategic responses to cyber breaches

Guides CISOs on strategically responding to cyber breaches and building organizational resilience.

 
pdf
Five tactical wins that move DPDP compliance from theory to practice

Five tactical wins that move DPDP compliance from theory to practice

Explores five practical strategies for implementing DPDP compliance.

 
pdf
Cybersecurity threats in Indian healthcare: 6 strategies to tackle them

Cybersecurity threats in Indian healthcare: 6 strategies to tackle them

Outlines 6 strategies to counter rising cybersecurity threats in India's healthcare sector.

 
pdf
CISO handbook: Cybersecurity metrics, budgeting, and leadership

CISO handbook: Cybersecurity metrics, budgeting, and leadership

Equips CISOs with guidance on cybersecurity metrics, budget planning, and security team leadership.

 
pdf
How to comply with ISO 27001:2022 security controls using SIEM

How to comply with ISO 27001:2022 security controls using SIEM

Explains how to achieve ISO 27001:2022 security controls compliance using a SIEM solution.

 
pdf
Continuously audit your environment to ensure PCI DSS 4.0 compliance

Continuously audit your environment to ensure PCI DSS 4.0 compliance

Guides organizations on continuously auditing their IT environment to meet PCI DSS 4.0 compliance.

 
pdf
How to improve risk scoring and threat detection with UEBA

How to improve risk scoring and threat detection with UEBA

Explores how UEBA capabilities improve threat detection accuracy and risk scoring.

 
pdf
The dark side of AI

The dark side of AI

Delves into the risks of AI misuse in cybersecurity, including AI-powered attack vectors.

 
pdf
Essential eight explained

Essential eight explained

Explains the Essential Eight cybersecurity maturity framework and how to implement it.

 
pdf
GDPR handbook

GDPR handbook

Covers everything organizations need to achieve and maintain GDPR compliance for data privacy.

 
pdf
How to detect and respond to cryptojacking attacks

How to detect and respond to cryptojacking attacks

Demonstrates how to detect and respond to cryptojacking attacks using a SIEM solution.

 
pdf
10 crucial audit reports for IT security

10 crucial audit reports for IT security

Highlights 10 essential audit reports that IT security teams should monitor regularly.

 
pdf
The basics of auditing and securing your network perimeter with SIEM

The basics of auditing and securing your network perimeter with SIEM

Guides organizations on auditing and securing network perimeter infrastructure using SIEM.

 
pdf
A security analyst's guide to understanding ransomware: The healthcare edition

A security analyst's guide to understanding ransomware: The healthcare edition

Helps security analysts understand ransomware tactics targeting healthcare organizations.

 
pdf
The IT security admin's guide to LGPD compliance

The IT security admin's guide to LGPD compliance

Walks IT admins through achieving LGPD (Brazil's data protection law) compliance using Log360.

 
pdf
How to implement the MITRE ATT&CK framework using Log360

How to implement the MITRE ATT&CK framework using Log360

Explains how to implement the MITRE ATT&CK framework in Log360 for structured threat detection.

 
pdf
Leveraging smart thresholds for accurate detection

Leveraging smart thresholds for accurate detection

Explores how smart thresholds in Log360 enable dynamic, low-noise anomaly detection.

 
pdf
How to calculate the cost savings from your SIEM implementation

How to calculate the cost savings from your SIEM implementation

Demonstrates how to calculate cost savings and ROI from deploying a SIEM solution.

 
pdf
How to streamline user identity mapping (UIM) for better anomaly detection

How to streamline user identity mapping (UIM) for better anomaly detection

Shows how effective user identity mapping (UIM) leads to more precise and reliable anomaly detection.

 
pdf
Threat intelligence and the SIEM advantage

Threat intelligence and the SIEM advantage

Covers how threat intelligence combined with SIEM enhances security visibility and response.

 
pdf
Using indicators to deal with security attacks

Using indicators to deal with security attacks

Explores how to leverage indicators of compromise (IoCs) and indicators of attack (IoAs) to detect threats.

 
pdf
The role of IT in achieving SOX compliance

The role of IT in achieving SOX compliance

Examines the role of IT and SIEM in helping organizations achieve SOX compliance.

 
pdf
ISO 27001 - Alert profile recommendations for ManageEngine Log360

ISO 27001 - Alert profile recommendations for ManageEngine Log360

Provides ISO 27001 alert profile recommendations for configuring Log360 effectively.

 
  • Use case videos
  • How-to videos
  • Webinar videos
How to leverage Log360 to detect defense evasion techniques on your network

How to leverage Log360 to detect defense evasion techniques on your network

Demonstrates how Log360 detects defense evasion techniques used by attackers on networks.

Detecting short-lived user accounts

Detecting short-lived user accounts

Explains how Log360 identifies short-lived user accounts created for malicious purposes.

Bringing down false positives

Bringing down false positives

Shows techniques to reduce false positive alerts and improve SOC alert quality with Log360.

Tracking critical metrics for security operations

Tracking critical metrics for security operations

Covers how to track and monitor critical security metrics in your security operations center.

Monitoring critical configuration changes

Monitoring critical configuration changes

Demonstrates how Log360 monitors and alerts on critical configuration changes across IT infrastructure.

How to monitor unusual system shutdowns & restarts

How to monitor unusual system shutdowns & restarts

Explains how Log360 detects and alerts on unusual system shutdown and restart events.

Log360's Incident Workbench in action

Log360's Incident Workbench in action

Showcases Log360's Incident Workbench in action for hands-on incident investigation.

ManageEngine Log360 and Endpoint Central integration

ManageEngine Log360 and Endpoint Central integration

Demonstrates the integration between Log360 and Endpoint Central for unified endpoint monitoring.

Log360 explains: Privilege escalation

Log360 explains: Privilege escalation

Explains privilege escalation attacks and how Log360 detects and alerts on them.

How to enable two-factor authentication in Log360?

How to enable two-factor authentication in Log360?

Walks through setting up two-factor authentication (2FA/MFA) for Log360 user logins.

How to apply the license file in Log360?

How to apply the license file in Log360?

Shows how to apply the license file to activate Log360 for seamless security operations.

How to configure General Logon settings and SSO settings in Log360?

How to configure General Logon settings and SSO settings in Log360?

Guides users through configuring general logon and Single Sign-On (SSO) settings in Log360.

How to import log data periodically in Log360?

How to import log data periodically in Log360?

Demonstrates how to set up periodic log data import schedules in Log360.

How to create a custom alert profile and associate it with a workflow rule in Log360?

How to create a custom alert profile and associate it with a workflow rule in Log360?

Explains how to build custom alert profiles and link them to workflow rules in Log360.

How to configure mail server in Log360?

How to configure mail server in Log360?

Shows how to configure mail server settings in Log360 for email notifications.

Detecting malicious traffic using threat intelligence and associating workflow profile with alert

Detecting malicious traffic using threat intelligence and associating workflow profile with alert

Demonstrates how to detect malicious traffic using threat intelligence and set up alert workflows.

Finding the needle in the haystack using Log360's advanced search capabilities

Finding the needle in the haystack using Log360's advanced search capabilities

Shows how to use Log360's advanced search to find specific log events across large datasets.

Detecting unauthorized data manipulation in Salesforce

Detecting unauthorized data manipulation in Salesforce

Explains how Log360 detects unauthorized data manipulation and changes in Salesforce.

How to spot archival tampering in Log360

How to spot archival tampering in Log360

Demonstrates how to spot signs of archival tampering and log deletion in Log360.

How to get alert for product update in Log360

How to get alert for product update in Log360

Shows how to configure Log360 to notify administrators when a product update is available.

Spotting malicious software installations

Spotting malicious software installations

Explains how Log360 detects unauthorized or malicious software installations across endpoints.

Detecting pass-the-hash attacks using Log360

Detecting pass-the-hash attacks using Log360

Demonstrates how Log360 detects pass-the-hash credential-based attacks using correlation rules.

Detecting credential dumping attacks using Log360

Detecting credential dumping attacks using Log360

Explains how Log360 detects credential dumping attacks such as those using Mimikatz.

How to manage threat feeds in Log360?

How to manage threat feeds in Log360?

Guides users through managing threat intelligence feeds and IOC sources in Log360.

How to automatically discover log sources in Log360?

How to automatically discover log sources in Log360?

Shows how to automatically discover log sources and devices in your network via Log360.

How to import vulnerability scanner data into Log360?

How to import vulnerability scanner data into Log360?

Demonstrates how to import vulnerability scanner data into Log360 for risk-aware alerting.

How to create and manage device groups in Log360?

How to create and manage device groups in Log360?

Explains how to create and manage device groups in Log360 for organized log management.

How to add vCenter source for monitoring in Log360?

How to add vCenter source for monitoring in Log360?

Walks through adding a vCenter source for monitoring virtual infrastructure in Log360.

Log management best practices for SIEM

Log management best practices for SIEM

Covers log management best practices and how SIEM enhances security operations.

Auditing and securing SQL and IIS

Auditing and securing SQL and IIS

Explores best practices for auditing and securing Microsoft SQL Server and IIS environments.

Auditing 101: Stay compliant and secure your enterprise with SIEM

Auditing 101: Stay compliant and secure your enterprise with SIEM

Explains how to stay audit-ready and secure the enterprise using SIEM-driven compliance.

Using event correlation to unravel security incidents

Using event correlation to unravel security incidents

Demonstrates how event correlation in Log360 helps identify and investigate security incidents.

Everything you need to know about ransomware

Everything you need to know about ransomware

Covers all aspects of ransomware—types, attack vectors, detection, and prevention.

Streamlining incident management using SIEM

Streamlining incident management using SIEM

Explains how to streamline the incident management lifecycle using SIEM capabilities.

The GDPR and SIEM

The GDPR and SIEM

Explores how SIEM solutions support GDPR compliance and data privacy management.

Beyond May 25th: What you need to do to prove your GDPR compliance

Beyond May 25th: What you need to do to prove your GDPR compliance

Guides organizations on what to do post-GDPR deadline to demonstrate ongoing compliance.

Top five critical alerts you need for IT security

Top five critical alerts you need for IT security

Highlights the top five critical security alerts every IT team should monitor.

5 steps that will save you from the GDPR violation penalty

5 steps that will save you from the GDPR violation penalty

Walks through five steps to achieve GDPR compliance using SIEM solutions.

Mastering enterprise security: Expert tips, best practices and real-world examples for businesses

Mastering enterprise security: Expert tips, best practices and real-world examples for businesses

Shares expert tips, best practices, and real-world examples for mastering enterprise security.

  •  

    We wanted to make sure that one, we can check the box for different security features that our clients are looking for us to have, and two, we improve our security so that we can harden our security footprint.

    Carter Ledyard

  •  

    The drill-down options and visual dashboards make threat investigation much faster and easier. It’s a truly user-friendly solution.

    Sundaram Business Services

  •  

    Log360 helped detect insider threats, unusual login patterns, privilege escalations, and potential data exfiltration attempts in real time.

    CIO, Northtown Automotive Companies

  •  

    Before Log360, we were missing a centralized view of our entire infrastructure. Now, we can quickly detect potential threats and respond before they escalate.Log360 has been invaluable for improving our incident response and ensuring compliance with audit standards. It’s a game-changer for our team.

    ECSO 911

 

Want to see these features in action?

Ensure smarter detection, faster response, and complete security across your organization with ManageEngine Log360.