2026 Log Collection Checklist — 10 Points Every Thai Organization Must Verify
Many organizations think they collect logs in full legal compliance, but gaps hide in the details. Verify your setup against this 10-point 2026 checklist.
Log Collection Checklist 2026 — 10 Points Every Thai Organization Must Verify
Are you confident your organization is collecting logs in full legal compliance? Many organizations think they collect logs, but in reality they may be incomplete, incorrect, or insecure — let's audit with this 10-point checklist.
✅ Point 1: Collect logs from every critical device
Identify devices that must be logged:
- ☐ Firewall (Palo Alto, Fortinet, Cisco ASA)
- ☐ Active Directory / LDAP
- ☐ VPN Gateway
- ☐ Email Server (Microsoft 365, Google Workspace)
- ☐ Web Server / Application Server
- ☐ Database Server
- ☐ Wi-Fi Controller / Access Point
- ☐ Endpoint (Antivirus, EDR)
💡 Tip: If you're unsure what devices you have, start with a Network Inventory first.
✅ Point 2: Retain logs for at least 90 days
Per Thailand's Computer Crime Act B.E. 2560, Section 26:
- Minimum 90 days of log retention
- May extend to 2 years in special cases
☐ Verify that log data from the past 90 days is still searchable.
✅ Point 3: Logs contain complete information
Collected logs must include at minimum:
- ☐ Timestamp (when the event occurred)
- ☐ Source IP / Destination IP
- ☐ Username (the user)
- ☐ Action (Login, Logout, Access, Deny, etc.)
- ☐ Status (Success, Failed)
✅ Point 4: Have tamper-protection for logs
Logs must not be modified or deleted:
- ☐ Use Hash Integrity (for example, SHA-256 under the organisation’s policy) to verify logs
- ☐ Use Write-Once or Immutable Storage
- ☐ Separate the Log Server from production servers
✅ Point 5: Encrypt log data
- ☐ Encrypt Data at Rest (AES-128 or higher)
- ☐ Encrypt Data in Transit (TLS 1.2+)
- ☐ Use Syslog over TLS instead of plain Syslog
✅ Point 6: Have access control
- ☐ Require Login/Password to access the log system
- ☐ Use RBAC (Role-Based Access Control)
- ☐ Maintain an Audit Log of administrators (who viewed what log, when)
✅ Point 7: Search logs quickly
- ☐ Search by IP, Username, Date Range
- ☐ Define and test response time against the project’s acceptance criteria
- ☐ Export results to PDF or CSV
📖 Read more: What is ICT Spec?
✅ Point 8: Have alerting for abnormal events
- ☐ Alert on repeated failed logins
- ☐ Alert when log storage disk reaches 80%
- ☐ Alert when a device stops sending logs
- ☐ Alert channels: Email, LINE, Microsoft Teams
✅ Point 9: Have monthly summary reports
- ☐ Report on log volume collected (EPS, Total Events)
- ☐ Report on abnormal events (Top 10 Alerts)
- ☐ Report on device status (Online/Offline)
- ☐ Report on log storage usage
✅ Point 10: Have backup and disaster recovery
- ☐ Backup logs at least weekly
- ☐ Test restoration at least annually
- ☐ Have a DR Site for the log server (if possible)
🎯 How many did you pass?
| Result | Level | Recommendation |
|---|
| 9–10 points | 🟢 Excellent | Ready for audit |
| 6–8 points | 🟡 Acceptable | Improve weak spots |
| 3–5 points | 🟠 At risk | Take action urgently |
| 0–2 points | 🔴 Dangerous | Review with the accountable owner and legal adviser |
⭐ zcrLog can support several checklist areas
zcrLog supports collection, search, alerting and reporting within the agreed deployment scope. Source coverage, retention, SLA and pricing must be confirmed against each project’s requirements and quotation.
🎯 View the zcrLog demo →
📞 Free consultation
Sources
Related articles
Continue with these related guides for the comparison and operating detail:
Related product
See zcrLog for the product scope, the pricing page for published prices, and the inputs to confirm with your delivery partner