Correlation

Event correlation is the process in which a SIEM relates a series of events to generate an incident or a more meaningful event. In our previous example, there were five failed login attempts to the same user account from multiple source machines. For a security analyst, it might be worth investigating this. Logging the correlation is the best way to raise alerts: 

Get Practical Network Scanning now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.