Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is a correlation rule?

A correlation rule links multiple events according to identifiers, order and timing so that a wider pattern can be detected. The link is a configured analytical relationship, not automatic proof of one cause or person.

Matching fields carry their own limitations

A rule might join login failures and a later success, or a new device and a permission change. It can match on account, device, IP address, session ID or a time window.

Shared accounts and addresses can join unrelated activity. Weak identifiers, duplicate ingestion and missing records can create an incomplete or misleading group. Events close in time are not necessarily causally connected.

Verify the proposed relationship event by event

Obtain the rule logic, match fields, time window, exclusions, sources and version. Preserve each underlying event and determine whether its identifiers actually refer to the same account, endpoint, session or process.

The rule may reveal a useful sequence that no single source exposes. Report that sequence with its supported links, while keeping causation, identity and incident boundaries as separate inferences.

The point to remember

Correlation rules propose relationships between events; investigators must verify the identifiers and must not equate correlation with causation.

Reference: LOG-104Logs, Records & Provider Evidence