Alert correlation

Source: Wikipedia, the free encyclopedia.

Alert correlation is a type of

NIDS and HIDS
computer systems, to form higher-level pieces of information.

Example of simple alert correlation is grouping invalid login attempts to report single incident like "10000 invalid login attempts on host X".

See also