International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1722629

1722629 Vol 3 · Issue 5 Download Paper

Automation of Log Collection and Incident Triage for Security Operations: A Review

Ifeanyichukwu Jeffrey Okwesa Daniel Ajiga Uzoamaka Iwuanyanwu

Subject area: Science,Engineering and Technology  ·  Area of research: Security Operations Automation

Abstract

Modern security operations centres (SOCs) ingest volumes of telemetry that far exceed the capacity of human analysts to inspect manually, and the resulting flood of alerts has made automation of log collection and incident triage a central concern for defensive practice. This paper reviews the research and engineering literature underpinning that automation, organising a fragmented body of work into a coherent picture spanning log collection and normalization, detection and correlation, automated triage and prioritization, security orchestration and automation, and the datasets used to evaluate these systems. We conduct a structured narrative review of works published up to 2019, complemented by seminal earlier contributions, and we synthesise them into a described taxonomy that maps each stage of the alert pipeline to its dominant techniques, inputs, and failure modes. The review shows that pattern-based log parsing and statistical anomaly detection have matured substantially, that alert correlation and adaptive classification can materially reduce analyst load, and that orchestration platforms increasingly encode triage as executable playbooks. Nevertheless, persistent challenges remain: high false-positive rates rooted in the base-rate fallacy, alert fatigue and analyst burnout, scarcity of labelled operational data, concept drift, and the weak external validity of widely used benchmark datasets. We argue that human factors, evaluation realism, and feedback-driven learning deserve as much attention as detection accuracy. The paper closes with future directions emphasising analyst-in-the-loop design, reproducible benchmarking, and resilience-oriented triage.

Keywords

security operations centre; log analysis; incident triage; SIEM; alert correlation; anomaly detection; alert fatigue; SOAR

How to cite this paper

Ifeanyichukwu Jeffrey Okwesa, Daniel Ajiga, Uzoamaka Iwuanyanwu "Automation of Log Collection and Incident Triage for Security Operations: A Review" Iconic Research And Engineering Journals Volume 3 Issue 5 2019 Page 627-650
Ifeanyichukwu Jeffrey Okwesa, Daniel Ajiga, Uzoamaka Iwuanyanwu "Automation of Log Collection and Incident Triage for Security Operations: A Review" Iconic Research And Engineering Journals, vol. 3, no. 5, Nov. 2019
Ifeanyichukwu Jeffrey Okwesa, Daniel Ajiga, Uzoamaka Iwuanyanwu (2019). Automation of Log Collection and Incident Triage for Security Operations: A Review. Iconic Research And Engineering Journals, 3(5).
Ifeanyichukwu Jeffrey Okwesa, Daniel Ajiga, Uzoamaka Iwuanyanwu "Automation of Log Collection and Incident Triage for Security Operations: A Review" Iconic Research And Engineering Journals, vol. 3, no. 5, Nov. 2019.
@article{1722629,
      author = {Ifeanyichukwu Jeffrey Okwesa, Daniel Ajiga, Uzoamaka Iwuanyanwu},
      title = {Automation of Log Collection and Incident Triage for Security Operations: A Review},
      journal = {Iconic Research And Engineering Journals},
      year = {2019},
      volume = {3},
      number = {5},
      pages = {627-650},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1722629.pdf},
      abstract = {Modern security operations centres (SOCs) ingest volumes of telemetry that far exceed the capacity of human analysts to inspect manually, and the resulting flood of alerts has made automation of log collection and incident triage a central concern for defensive practice. This paper reviews the research and engineering literature underpinning that automation, organising a fragmented body of work into a coherent picture spanning log collection and normalization, detection and correlation, automated triage and prioritization, security orchestration and automation, and the datasets used to evaluate these systems. We conduct a structured narrative review of works published up to 2019, complemented by seminal earlier contributions, and we synthesise them into a described taxonomy that maps each stage of the alert pipeline to its dominant techniques, inputs, and failure modes. The review shows that pattern-based log parsing and statistical anomaly detection have matured substantially, that alert correlation and adaptive classification can materially reduce analyst load, and that orchestration platforms increasingly encode triage as executable playbooks. Nevertheless, persistent challenges remain: high false-positive rates rooted in the base-rate fallacy, alert fatigue and analyst burnout, scarcity of labelled operational data, concept drift, and the weak external validity of widely used benchmark datasets. We argue that human factors, evaluation realism, and feedback-driven learning deserve as much attention as detection accuracy. The paper closes with future directions emphasising analyst-in-the-loop design, reproducible benchmarking, and resilience-oriented triage.},
      keywords = {security operations centre; log analysis; incident triage; SIEM; alert correlation; anomaly detection; alert fatigue; SOAR},
      month = {November},
  }