Log correlation: Part 2
Dario Valentino Forte · Computer Fraud & Security · 2004
This is the second article in a three part series on log correlation. The third and final part will be published in Computer Fraud & Security , August edition. Log file correlation is related to two distinct activities: Intrusion Detection and Network Forensics . It is more important than ever that these two disciplines work together in a mutualistic relationship in order to avoid Points of Failure. This paper, intended as a tutorial for those dealing with such issues, presents an overview of log analysis and correlation, with special emphasis on the tools and techniques for managing them within a network forensics context.