List of questions
Related questions
Question 39 - PCSAE discussion
What is the most effective way to correlate multiple raw events coming from a SIEM and link them together?
A.
Process all alerts by running the respective playbook and link related incidents during postprocessing
B.
Ingest all raw events, run a custom script to find the relationship between them and proceed to link them together
C.
Configure a pre-process rule to link related events as they are ingested
D.
Manually go through the incidents created by the raw events and link related incidents
Your answer:
0 comments
Sorted by
Leave a comment first