correlation manager

The component that performs automated, real-time correlation, aggregation, and filtering of events, as well as incident creation. To perform these functions, correlation manager uses a set of rule files and a knowledge base to compare events to patterns of common network security threats.

