After a defense layer has been established machines still need to be Monitored and Logged regularly to determine if any active attacks are in progress. There are various tools to log and monitor files which can parse output and format it in a more easily readable way.