Correlation involves relating several events.
Let's take a simple example.
A SIEM receives:
Event 1
47 failed authentication attempts on one account.
Then :
Event 2
Authentication successful from an unusual IP address.
Then :
Event 3
Creating a new administrator account.
Then :
Event 4
Access to multiple critical servers.
Then :
Event 5
Executing PowerShell.
Individually, these events may not trigger a critical alert.
When correlated, they can constitute a much more significant attack scenario.
The SIEM can then generate an alert of the following type:
“Suspected compromise of a privileged account.”
This capability constitutes a fundamental difference between:
collect logs
And
to actually use logs to detect threats.