CMMC Practice AU.L2-3.3.5

Audit Correlation: Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.

Monarch ISC Guidance

The practice is expressly requiring you to review audit logs across all your systems, not just a select one or two hosts. By now, you've recognized the importance of implementing a SIEM, and this will do this for you. The ability to review events across multiple systems in a given time period, or for a given user, is invaluable in forensic investigations. This list of systems being collectively audited in the SIEM should be reviewed regularly to ensure that new systems have been added to the process.

Discussion From Source

NIST SP 800-171 R2 Correlating audit record review, analysis, and reporting processes helps to ensure that they do not operate independently, but rather collectively. Regarding the assessment of a given organizational system, the requirement is agnostic as to whether this correlation is applied at the system level or at the organization level across all systems.

References