Home / Current Issue / Paper 1722629
Automation of Log Collection and Incident Triage for Security Operations: A Review
Subject area: Science,Engineering and Technology · Area of research: Security Operations Automation
Abstract
Modern security operations centres (SOCs) ingest volumes of telemetry that far exceed the capacity of human analysts to inspect manually, and the resulting flood of alerts has made automation of log collection and incident triage a central concern for defensive practice. This paper reviews the research and engineering literature underpinning that automation, organising a fragmented body of work into a coherent picture spanning log collection and normalization, detection and correlation, automated triage and prioritization, security orchestration and automation, and the datasets used to evaluate these systems. We conduct a structured narrative review of works published up to 2019, complemented by seminal earlier contributions, and we synthesise them into a described taxonomy that maps each stage of the alert pipeline to its dominant techniques, inputs, and failure modes. The review shows that pattern-based log parsing and statistical anomaly detection have matured substantially, that alert correlation and adaptive classification can materially reduce analyst load, and that orchestration platforms increasingly encode triage as executable playbooks. Nevertheless, persistent challenges remain: high false-positive rates rooted in the base-rate fallacy, alert fatigue and analyst burnout, scarcity of labelled operational data, concept drift, and the weak external validity of widely used benchmark datasets. We argue that human factors, evaluation realism, and feedback-driven learning deserve as much attention as detection accuracy. The paper closes with future directions emphasising analyst-in-the-loop design, reproducible benchmarking, and resilience-oriented triage.
Keywords
security operations centre; log analysis; incident triage; SIEM; alert correlation; anomaly detection; alert fatigue; SOAR
How to cite this paper
@article{1722629,
author = {Ifeanyichukwu Jeffrey Okwesa, Daniel Ajiga, Uzoamaka Iwuanyanwu},
title = {Automation of Log Collection and Incident Triage for Security Operations: A Review},
journal = {Iconic Research And Engineering Journals},
year = {2019},
volume = {3},
number = {5},
pages = {627-650},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1722629.pdf},
abstract = {Modern security operations centres (SOCs) ingest volumes of telemetry that far exceed the capacity of human analysts to inspect manually, and the resulting flood of alerts has made automation of log collection and incident triage a central concern for defensive practice. This paper reviews the research and engineering literature underpinning that automation, organising a fragmented body of work into a coherent picture spanning log collection and normalization, detection and correlation, automated triage and prioritization, security orchestration and automation, and the datasets used to evaluate these systems. We conduct a structured narrative review of works published up to 2019, complemented by seminal earlier contributions, and we synthesise them into a described taxonomy that maps each stage of the alert pipeline to its dominant techniques, inputs, and failure modes. The review shows that pattern-based log parsing and statistical anomaly detection have matured substantially, that alert correlation and adaptive classification can materially reduce analyst load, and that orchestration platforms increasingly encode triage as executable playbooks. Nevertheless, persistent challenges remain: high false-positive rates rooted in the base-rate fallacy, alert fatigue and analyst burnout, scarcity of labelled operational data, concept drift, and the weak external validity of widely used benchmark datasets. We argue that human factors, evaluation realism, and feedback-driven learning deserve as much attention as detection accuracy. The paper closes with future directions emphasising analyst-in-the-loop design, reproducible benchmarking, and resilience-oriented triage.},
keywords = {security operations centre; log analysis; incident triage; SIEM; alert correlation; anomaly detection; alert fatigue; SOAR},
month = {November},
}