Home / Companies / Tyk / Blog / Post Details
Content Deep Dive

OWASP API security – 10: Insufficient logging & monitoring

Blog post from Tyk

Post Details
Company
Tyk
Date Published
Author
Jennifer Craig
Word Count
939
Company Posts That Month
13
Language
English
Hacker News Points
-
Post removed?
No
Summary

Insufficient logging and monitoring, while not a direct vulnerability, leaves organizations blind to current and past attacks, making them susceptible to future breaches. Effective logging and monitoring require both application and transaction logs to be secured in separate storage and analytics systems. This ensures that, even if a system is compromised, forensic data remains trustworthy. The Tyk API Gateway enhances data collection by integrating with third-party tools and providing features such as increased log verbosity and real-time event handling. By differentiating but not separating application and transaction logs, organizations can better detect and analyze attacks. It is crucial to maintain synchronized timestamps across systems to aid in correlating attacks and ensure timely alerts for any discrepancies.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Real-time 1 1,102 330 114 -6%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.