#SIEM #security #logs #blue , I would rather threat hunt but here we are. Does it make sense to catalog all log sources and have an example for each one? #knowyourdata right? When is too much documentation too much ? It makes sense to me I guess to catalog all sources than document where the logs would go in a #datamodel and how to query them.