# What is Security Telemetry?

> Security telemetry is the security-relevant evidence generated by systems, identities, endpoints, applications, networks, cloud services, and protective controls.

- Canonical URL: https://yellowcube.eu/glossary/security-telemetry/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It can include logs, events, metrics, traces, flows, packet data, configuration state, and changes. Telemetry gives defenders observations from which they can investigate activity, build detections, and assess whether controls are working.

Collection alone is not enough. Useful telemetry needs trustworthy timestamps, source and identity context, consistent schemas, adequate retention, controlled access, and an understood path from generation to analysis. Owners should collect for defined security purposes and balance visibility against privacy, storage cost, and the risk of creating another sensitive data repository.

### Key points

- **Source design:** Identify the questions and detections a source must support before deciding which events and fields to collect.
- **Quality controls:** Monitor completeness, latency, parsing, time synchronization, duplication, schema changes, and collection failures.
- **Governance:** Set proportionate access, retention, minimization, integrity, and deletion rules, especially where events contain personal or confidential data.
- **Important limitation:** Telemetry is evidence, not truth. It may be incomplete, ambiguous, manipulated, or stripped of context, so high-impact conclusions should be corroborated.

### Related terms

[Security information and event management (SIEM)](<https://yellowcube.eu/glossary/security-information-and-event-management/>) · [Detection engineering](<https://yellowcube.eu/glossary/detection-engineering/>) · [Artificial intelligence for IT operations (AIOps)](<https://yellowcube.eu/glossary/artificial-intelligence-for-it-operations/>)

### Sources

[NIST SP 800-137](https://csrc.nist.gov/pubs/sp/800/137/final) · [NIST SP 800-92](https://csrc.nist.gov/pubs/sp/800/92/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

