AU-6 Audit Log Review: Same SIEM, Different Evidence
Two agencies. Same checklist answer: audit logs are collected and reviewed. Both had a SIEM deployment. Both rated AU-6 compliant.
The auditor asked for the review records from the past 90 days.
Agency A opened the SIEM dashboard. Logs were present. The retention window was 90 days. Alerts were configured. The auditor asked who reviewed the logs, on what schedule, and where the review findings were recorded. Agency A explained that the SIEM generates alerts when thresholds are crossed. The auditor clarified: not the alerts — the review. The scheduled, deliberate review of audit records for indications of inappropriate or unusual activity that may not have triggered an automated alert. That record did not exist.
Agency B produced a review log: 13 weekly review entries over the past 90 days, each showing the reviewer's name, the date, the log categories examined, any findings, and disposition. Three entries noted anomalies that were investigated and closed. Ten entries noted no findings requiring escalation.
The auditor noted Agency A's finding: AU-6 requires review and analysis of audit records, not collection and alerting. The log is the infrastructure. The review is the control.
What the control actually requires
AU-6(a) requires the organization to review and analyze system audit records at a defined frequency for indications of inappropriate or unusual activity. The defined frequency in v6.1 guidance is at minimum weekly for key event categories. AU-6(b) requires that review findings be reported to defined personnel.
Alert-driven monitoring is not equivalent to scheduled review. Alerts catch known patterns that were configured in advance. Scheduled review catches what the alert configuration did not anticipate. Both are necessary. AU-6 requires the scheduled review and a record of it.
What the auditor is looking for
A defined review cadence in the policy or procedure. Named individuals or roles responsible for conducting reviews. A review log with dates, scope, findings, and disposition. Evidence that anomalies discovered during review were acted upon. Reporting records showing findings were communicated to the appropriate personnel.
A SIEM with 90 days of logs and no review record shows that data was collected. It does not show that AU-6 operated.
The common failure mode
The SIEM was deployed, alerts were configured, and the team moved on. Alert response is well-practiced. Scheduled review was never established as a separate, documented activity. The assumption was that alerting and reviewing were the same thing. They are not.
Written by Dr. Alexis W. Perdereaux-Weekes
DBA · CISA · CISM · CRISC · CDPSE
Founder, CJIS360 LLC
Sources: CJIS Security Policy v6.1, 06/25/2026 — AU-6 Audit Record Review, Analysis, and Reporting; CA-7 Continuous Monitoring; §1.4 Terminology Used in This Document.