A system and method for analyzing events from devices relating to network
security, includes a device interface(s), for receiving events from
devices. One or more processors, responsive to the event received
pursuant to the device interfaces, evaluate the event in accordance with
rules, wherein the rules define, inter alia, an operation the system is
to take to evaluate the event and an action to be taken under specified
conditions. Also, the processor can determine, responsive to the received
event, whether the event is of interest, and if not, discarding the
event. The processor can provide a correlation corresponding to the at
least one event, for the rules.