{"ok":true,"trend":{"id":463419,"platform":"mastodon","region":"global","key":"the first questions in any incident are dull ones. what happened. who logged in, from where, when. every one of them is","title":"The first questions in any incident are dull ones. What happened. Who logged in, from where, when. Every one of them is","url":"https://infosec.exchange/@adrianhollister/117359018045887737","first_seen":"2026-09-30T08:47:47.944230Z","last_seen":"2026-09-30T08:47:47.944230Z","last_rank":10,"peak_rank":6,"last_volume":1,"peak_volume":1,"seen_count":1,"score":0.81875,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"Cybersecurity practitioner Adrian Hollister argues that incident response starts with mundane questions — what happened, who logged in, and when — all answerable only through logs. He highlights two recurring failure modes, including retention windows shorter than an attacker's patience, noting the UK's National Cyber Security Centre recommends keeping logs for at least six months.","why":"Practitioners are debating common log management failures that undermine security incident investigations.","tone":"neutral","entities":["Adrian Hollister","NCSC","Infosec Exchange"],"summarized_at":"2026-09-30T08:49:15.940228Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1282},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Security experts stress log retention as core incident response practice","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-09-30T08:47:47.944230Z","rank":6,"volume":1},{"captured_at":"2026-09-30T08:47:47.944230Z","rank":10,"volume":1}],"posts":[{"platform":"mastodon","url":"https://infosec.exchange/@adrianhollister/117359018045887737","author":"adrianhollister@infosec.exchange","title":null,"snippet":"The first questions in any incident are dull ones. What happened. Who logged in, from where, when. Every one of them is answered by logs or not answered at all. Two failure modes repeat. The first is retention shorter than the attacker's patience. The NCSC suggests six months…","posted_at":"2026-09-30T08:21:40Z","likes":1}],"elsewhere":[],"window":"7d"}}