The process of linking events from different logs to provide a comprehensive view of activity across systems and networks. Log correlation helps identify and understand complex security incidents and advanced persistent threats (APTs).
Real-World Examples
SIEM systems use log correlation to track suspicious activities across multiple devices.