When a SIEM system aggregates logs from diverse sources, what specific process does it perform to identify a complex attack that spans multiple devices?
The specific process a SIEM system performs to identify a complex attack spanning multiple devices is called correlation. Correlation is the logical linking of related events from different sources to detect patterns that suggest a coordinated threat. Because individual devices generate thousands of logs that look normal in isolation, the SIEM system uses correlation rules to compare logs....
Community Answers
Sign in to open profiles and full community answers.
No community answers yet. Be the first to submit one.