Alert Correlation
Definition
The process of grouping multiple related events or alerts into a single higher-level alert representing one attack sequence. A correlation rule might group a failed-login burst followed by a successful login from the same IP as a single brute-force alert rather than hundreds of individual login-failure alerts.
- Purpose
- Group related alerts into one higher-level alert
- Example
- Failed-login burst plus success from same IP as one brute-force alert
- Benefit
- Reduces alert volume presented to analysts
- Mechanism
- Correlation rules across event streams
Common questions
Why not just let analysts review every individual alert separately?+
A single attack sequence can generate hundreds of low-level events, and reviewing each in isolation obscures the bigger pattern, so correlation surfaces the attack as one prioritised item instead of burying it inside a flood of individually unremarkable entries.
Can poorly tuned correlation rules cause an investigator to miss something?+
Yes, if a correlation rule groups events too aggressively it can merge an unrelated event into an existing alert or suppress a genuinely distinct incident that happens to share surface features with a known benign pattern, so rule tuning is an ongoing task.
Related terms
- Alert Fatigue
- The condition in which analysts receive more alerts than they can meaningfully review, leading to delayed responses, dismissed true positives, and reduced...
- EDR (Endpoint Detection and Response)
- An agent-based security tool deployed on individual endpoints (workstations, servers, mobile devices) that monitors process execution, file changes, network connections, and registry...
- IDS/IPS (Intrusion Detection/Prevention System)
- Network or host-based systems that inspect traffic or system calls for known attack patterns. An IDS generates alerts without blocking; an IPS...
- Indicator of Compromise (IoC)
- An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
- SIEM (Security Information and Event Management)
- A platform that aggregates log and event data from systems, networks, and applications across an environment, correlates events against detection rules, generates...