Correlation Rules - BEST PRACTICES

"Bruno Moraes" <[email protected]>
Newsgroups gmane.comp.sysutils.loganalysis
Message-ID <[email protected]>
Dear All,
Good morning. I'm study about techniques of creation correlation rules. There are many log management tools in the market with native correlation rules in the software....
I need create a list of correlation rules that isn't native in the sec tool to my environment.
First Example that i thought: Create one correlation rule that alert when the users make duplicate login in the network..
What you have seen as best practices about creation of correlation rules user-defined? What are the best examples?
Other example: Log Integration between firewall x ids ... 
Any suggestion?
Many thanks for attention.
Bernard

_______________________________________________
LogAnalysis mailing list
[email protected]
http://www.loganalysis.org/mailman/listinfo/loganalysis
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.