StudyToCert

All certifications / CySA+ / Lessons

CompTIA CySA+ CS0-004 · Domain 1: Security operations

Logging: log ingestion, time synchronization (NTP), log levels, Windows Event IDs, Sysmon, Linux auth logs

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Logs are the analyst's primary evidence. If a system does not log an event, or the log never reaches your central platform, you cannot detect it or investigate it later. CySA+ expects you to know how logs are collected, why their timestamps must agree, how severity levels work and which specific events on Windows and Linux tell you something important.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CySA+ for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CySA+ study plan