ABSTRACT

Let’s now look at what to do with our multitude of events that the system can now generate. We covered collection, correlation, and intelligent interpretation of log and event data which is a large part of our picture, but we must also give thought to what to do with the events, reports, and general output once they are actually in our possession. In this section we walk through various alerting cases based on previous reporting scenarios and attempt to create a high-level response mechanism as well as an opportunity to use the data.