# ACSC Publishes SIEM Log Collection Guidance

The Australian Cyber Security Centre (ACSC) has released detailed practitioner guidance on priority log categories for ingestion by Security Information and Event Management (SIEM) platforms, specifically targeting large organizations and government entities. This guidance outlines prioritized logging from endpoints, network devices, Microsoft domain controllers, cloud platforms, and operational technology, emphasizing the need for organizations to tailor log collection strategies based on their unique risk profiles. It also highlights phased implementation approaches and the importance of collaboration with cloud service providers under shared responsibility models to optimize threat detection and response capabilities.

- **Why this matters:** Procurement professionals should consider this guidance when specifying cybersecurity requirements for SIEM solutions and related services to ensure alignment with best practices and risk-based prioritization.
- Organizations can leverage this resource to refine contract scopes around log management, data ingestion, and cloud security responsibilities.
- Vendors offering SIEM platforms and managed security services may find opportunities to tailor offerings that support phased log ingestion and integration with cloud environments.
- This guidance underscores the growing emphasis on comprehensive, risk-informed cybersecurity procurement strategies within government and large enterprise sectors.

**Jurisdictions:** federal
**Industries:** Public Safety, Information Technology
**Topics:** Cybersecurity, Digital Infrastructure
**Published:** September 18, 2026

### Government Entities
- Australian Cyber Security Centre (ACSC)

### Key Quotes
> The recommendations in this publication should be treated as generic advice; each organisation should tailor the collection, centralisation, and analysis of logs to its specific environment and risk profile.
> — Original poster

### Sources
- [Log collection tool](https://www.reddit.com/r/cybersecurity/comments/1wjshk1/log_collection_tool) - reddit-cybersecurity