Event correlation is the process in which a SIEM relates a series of events to generate an incident or a more meaningful event. In our previous example, there were five failed login attempts to the same user account from multiple source machines. For a security analyst, it might be worth investigating this. Logging the correlation is the best way to raise alerts: