Skip to content

Commit 5854b59

Browse files
Update _posts/2025-03-05-OpenSearch-as-a-SIEM-Solution.md
Co-authored-by: Nathan Bower <[email protected]> Signed-off-by: DattellConsulting <[email protected]>
1 parent 81fc797 commit 5854b59

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

_posts/2025-03-05-OpenSearch-as-a-SIEM-Solution.md

+1-1
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ A powerful feature of OpenSearch Security Analytics is its ability to correlate
3434

3535
For example, a sequence of events like a VPN login from a new location followed by a privileged action in a server log and an abnormal outbound network connection could be correlated into one incident.
3636

37-
The correlation engine uses defined rules (correlation rules) to specify these multi-step threat scenarios and can display a visualization (a correlation graph) of how disparate events relate to each other.
37+
The correlation engine uses defined rules ("correlation rules") to specify these multi-step threat scenarios and can display a visualization (a "correlation graph") of how disparate events relate to each other.
3838

3939
This cross-log correlation increases confidence that an alert represents a real incident by combining clues from various sources. Such capabilities, typically found in advanced SIEMs, help analysts see the bigger picture of an attack and reduce false positives.
4040

0 commit comments

Comments
 (0)