Correlation needs a shared identifier
Joining two sources requires a field that means the same thing in both. Most estates find out during an incident that they do not have one.
Correlation sounds like a platform feature. It is mostly a data problem.
To connect a VPN session to a workstation logon, something has to appear in both
records and mean the same thing in both. A username, perhaps. Except the VPN
logs slipare, the identity provider logs slipare@company.com, the endpoint
logs COMPANY\slipare, and the HR system logs an employee number.
Four labels, one person, and nothing in your platform knows they are related unless somebody sat down and told it.
Hostnames are worse, because they are not stable. One laptop has a short name, a fully qualified name, an asset tag, a serial number, and an address that rotates. The address is the field most rules reach for and the one that means the least, because last week it belonged to somebody else.
So the work that pays off is boring and happens long before you need it. Normalise identities to one canonical form at ingest. Keep a mapping from every host identifier you see back to a single asset record. Carry a session or request identifier through the systems capable of emitting one.
Pick two sources you would certainly need together during an intrusion. Name the field that joins them. If it takes you longer than ten seconds, you do not have one yet.
CHECK YOURSELF
During an investigation you need to connect activity in a cloud audit log to a specific laptop. The audit log records a public IP address. Why is that often not enough?
SHOW THE ANSWER
Many devices share one public address, and the mapping behind it changes over time
Why. Address translation puts a whole office or VPN pool behind a handful of public addresses, so the value identifies an egress point rather than a machine, and the internal lease sitting behind it moves. Answering the question needs whatever recorded that mapping at that moment, usually DHCP or the VPN concentrator, and those records carry their own much shorter retention. The other three describe things that are not generally true: cloud audit logs do record source addresses, the log is at rest and readable, and address formatting is one of the few genuinely consistent fields across sources.