Automated Log Review

PCIComplianceHubLast updated

The use of tooling, such as a SIEM or log analytics platform, to review audit logs and surface anomalies, rather than relying on people reading logs by hand. PCI DSS Requirement 10.4.1.1 requires automated mechanisms for the daily review of security-critical logs, on the reasoning that manual review does not scale to the log volume a modern environment produces. This was future-dated at publication and became mandatory on 31 March 2025.

In PCI DSS v4.0.1. 10.4.1, 10.4.1.1