
Amazon Web Services (AWS)

AWS ALB Logs
AWS Application Load Balancer (ALB) access logs capture detailed information about requests sent to the load balancer, including client IP addresses, request paths, server responses, latencies, and TLS negotiation details. These logs are stored in Amazon S3 and provide granular visibility into application traffic patterns and potential security events.
ALB logs are essential for security monitoring as they reveal suspicious request patterns, potential web application attacks, unauthorized access attempts, and traffic anomalies. When integrated with a SIEM or XDR platform, they enable security teams to detect and investigate threats targeting web applications, including brute force attacks, SQL injection attempts, and reconnaissance activity.
Sophos Products
Sophos MDR/XDR Integrations
Partner Technology
Cloud
Solution Category
Sophos MDR/XDR Integrations