The process of collecting log data from multiple sources into a centralized system for analysis.
Without log aggregation, investigating an incident means manually checking dozens of separate systems — SIEM platforms exist specifically to solve this problem.