You have central logging going, detailed app logging/alerting (e.g. modsec), network based security alerting (e.g. snort), and whatever else feeding your observation deck.
Do you have any cool techniques you’d like to share for how you relate security events?
How about tools? (in-house is fine, just describe what it does)