Tiger Shark has a nice write up but his tools are a little old.
Actually you can replace all those with PureSecure's replacement Sentarus
Theres a free HomeAdmin edition but it does require a dedicated box.
When used with the host agents you can parse out text logs on any *nix of Win32 system, monitor Win32 event logs and a ton of other stuff.

Im not sure about log correlation though. I know it correalates logs to network attacks but it doesnt correlate log files between log files on other hosts. That would take some manual work but at least all you can parse all your log files from different hosts and display it all on one page and set threshold for occurences.

Heres a link to HomeAdmin:
http://www.demarc.com/downloads/sentarus_fm/