What is the primary purpose of a SIEM system in network forensic investigations?
-
A
To encrypt all network traffic for secure storage
-
B
To aggregate and correlate log data from multiple sources for threat detection
-
C
To perform deep packet inspection on all traffic in real time
-
D
To automatically patch vulnerabilities discovered during investigations