Event correlation techniques are designed to detect events, make sense of them and assign the appropriate control action. As data becomes more complex, the need for correlation intelligence will continue to increase in significance.
LOGTITAN SIEM correlation engine has many advanced features. One of them is “Never Seen Before” type of rules.
This type of rules starts to collect values immediately. Collects values during the learning phase and then monitor for any value that has not seen before.