Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is event correlation?

Event correlation links records that may describe the same activity, session, transaction or incident. It builds a supported cross-system sequence; it does not turn proximity into common cause.

Request, transaction, session and message IDs can be strong within their defined systems. Accounts, device names, hashes, IP addresses and time can support a link but may be shared, duplicated or reused.

Several compatible identifiers and a technically plausible sequence are stronger than one approximate timestamp. Imported events must also be recognised so that duplicate representations are not treated as independent corroboration.

Make the correlation reasoning reviewable

Record sources, matching fields, permitted time window and assumptions. Check clock offset, retries, automation and ingestion delay where records appear not to align. Reject a proposed link when identifier scope or workflow is incompatible.

The conclusion should say why events are probably connected and what remains uncertain, rather than replacing the source chain with an unsupported narrative.

The point to remember

Correlation is strongest when scoped identifiers and technical sequence agree across independently understood records.

Reference: LOG-133Logs, Records & Provider Evidence