Log Correlation
Definition
The process of matching related events from different log sources using shared attributes such as IP address, username, timestamp, or session ID. Correlation transforms individual raw log lines into higher-level events that carry investigative meaning.
- Input
- Related events from different log sources
- Matching keys
- IP address, username, timestamp, session ID
- Output
- Higher-level events with investigative meaning
- Field
- Network and SIEM forensics
Common questions
Why is log correlation necessary rather than reviewing each log source separately?+
Individual raw log lines rarely tell the full story on their own; correlating them across sources reconstructs the actual sequence of an attacker's or a user's actions across systems.
What commonly complicates log correlation across sources?+
Inconsistent timestamp formats or clock drift between systems, which is why normalising timestamps to a common baseline typically has to happen before correlation can be trusted.
Related terms
- Alert Triage
- The process of reviewing SIEM-generated alerts to determine which are genuine security events and which are false positives. In forensic investigations, alert...
- Chain of Custody
- The documented chronological record of who collected, handled, transferred, and examined a piece of evidence. For digital evidence, chain of custody includes...
- Normalisation
- The process of converting log data from different vendors and formats into a common schema so that fields can be compared across...
- Retention Policy
- An organisation's rule specifying how long log data is stored before deletion or archiving. Policies are typically driven by compliance requirements and...
- SIEM
- Security Information and Event Management. A platform that ingests log streams from multiple sources, normalises them to a common schema, and applies...