Event correlation is the process in which a SIEM relates a series of events to generate an incident or a more meaningful event. In our previous example, there were five failed login attempts to the same user account from multiple source machines. For a security analyst, it might be worth investigating this. Logging the correlation is the best way to raise alerts:
Correlation
Get Practical Network Scanning now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.