Log file correlation is related to two distinct activities: intrusion detection and network forensics. It is more important than ever that these two disciplines work together in a mutualistic relationship in order to avoid points of failure. This paper, intended as a tutorial for those dealing with such issues, presents an overview of log analysis and correlation, with special emphasis on the tools and techniques for managing them within a network forensics context. The paper has been split in two parts and part 2 will appear next month in Computer Fraud & Security , July edition.
No takes yet. Share an insight, caveat, or question.
Dario Forte (2004) studied this question.
Synapse has enriched 2 closely related papers on similar clinical questions. Consider them for comparative context: