Rule-Based Event Correlation: Difference between revisions
Appearance
imported>Unknown user No edit summary |
imported>Unknown user No edit summary |
(No difference)
| |
imported>Unknown user No edit summary |
imported>Unknown user No edit summary |
(No difference)
| |
Correlating events by matching multiple log entries from a single source or multiple sources based on logged values, such as timestamps, IP addresses, and event types.
Source: NIST SP 800-92 | Category: