
All alone, it’s easy to understand that this log event represents a port 445
probe from the Internet along with where it tried to go and then to access its
threat as an individual event. However, in the real world, this log event will be
buried along with thousands of other entries in the log file, so it could easily
be missed. Further, we need to look at many such entries to determine if the
destination server is being targeted, if there is a port scan going on or
widespread port 445 activity, or if it is just an isolated event.
In addition, the most important information needs to be archived so it is
available for a deeper analysis when necessary