In the last few weeks we had a busy schedule; projects were piling up, there were some assignments that were needed to be finished and some studying to be done (Glad its all over now 🙂 ) This week, we discussed about our paper which was to be presented to the class before our midterms. This paper was one of the most challenging task for us as a group because we got something that not everyone in the group understood because it was a new word or a new terminology. It was Correlation. Correlation is a technique wherein the logs are compared and filtered out so that only the important logs are left out after the correlation is applied. I was amazed that this kind of technique existed! (WOW). Adrian said to me that this is important in log management because every day, thousands of logs are recorded and sometimes there are some false positives and sometimes there are really important logs on the log servers or where the logs are gathered each day. Sir Justin also explain to us briefly on what correlation is.
For me, it’s a new term and hearing the word correlation makes me want to discover and research more about it! I know it will be useful and I am certain that there are more explanations about correlation from other researches. Just like Sir Justin’s paper, they indicated that there should be log consolidation and event management into SIEM. It just goes to show you how important correlation is to a log management system. Earlier this day, was the day of our presentation and we were so nervous because we were about to report in front of the whole class! And Sir Pineda said that if we didn’t have the right answer for each of our blockmates’ question, we get a deduction (was so scared of this HAHAHAHA) but it turned out to be just a joke!!! Hahahaha Long story short, we were able to portray to the class what correlation is and how helpful it is to the IDS or any monitoring system 🙂 Thanks for reading!!!