in Use Cases

by
Generally in SIEM based on use cases correlation rule is written which is basically a like a regular expression which matches with the event to cause an action(alert). This action is scheduled for specific time intervals with respect to the events in the SIEM. In short correlation rule triggers the alerts on SIEM
by
when logs matches certain correlation rules in the SIEM, the alerts are triggered

