Palisade Magazine

 

Discuss: Application Logs - Security Best Practices

by Dipesh Rawal, CISA
Discussion is open — there are 2 reader comments. Add yours.
1. Dharmesh Mehta | 21 Oct 2005 5:23 PM

In certain environments, the IP Address of the user may not be a reliable parameter for identification, as in the case if Internet-facing applications or if the application is hosted behind proxies or loadbalancers.

In that case, either ignore the IP Address or log the information in the Client-IP or Via HTTP Headers

Short but useful checklist. Thanks.

Post Your Comment








Please keep your comments on topic. Fields marked with * are required. We reserve the right to remove any comments deemed inappropriate.


*