How should linked events across several systems be correlated?¶
Link cross-system events using several shared identifiers and a technically plausible sequence. Proximity in time is supporting context, not proof that events belong together.
Preserve native time and identity¶
Retain original timestamps, zones, clock information and collection delay. Useful joins include session and correlation IDs, stable accounts, hosts, process IDs, hashes, commands and management-job identifiers.
Identify gateways, proxies and platforms between systems. One component may record the request, another authentication and a third the resulting process; the apparent source at each layer may differ.
Avoid false corroboration¶
Shared or service accounts can generate overlapping sessions, so do not merge activity from account name alone. Record gaps and conflicts rather than forcing one uninterrupted narrative.
Several alerts may also derive from the same underlying event. Preserve their shared event IDs and distinguish primary records from product interpretations, so one authentication is not counted as several independent facts.
Key takeaway
Correlate events through multiple native identifiers, clocks and intermediaries, while keeping derived alerts and unresolved gaps visible.