Jump to content

Alert correlation

From Wikipedia, the free encyclopedia
This is the current revision of this page, as edited by Tea2min (talk | contribs) at 11:47, 20 April 2023 (Move out of Category:Computable analysis, completely unrelated topic.). The present address (URL) is a permanent link to this version.
(diff) ← Previous revision | Latest revision (diff) | Newer revision → (diff)

Alert correlation is a type of log analysis. It focuses on the process of clustering alerts (events), generated by NIDS and HIDS computer systems, to form higher-level pieces of information.

Example of simple alert correlation is grouping invalid login attempts to report single incident like "10000 invalid login attempts on host X".

See also

[edit]