Skip to content

Log Normalisation

Definition

The conversion of log entries from their native format into a common schema, typically a structured record with a corrected UTC timestamp, source address, destination address, protocol, and action field. Normalisation makes cross-source comparison programmatic rather than manual.

Purpose
Convert log entries into a common schema
Typical fields
Corrected UTC timestamp, source/destination address, protocol, action
Benefit
Enables programmatic cross-source comparison

Common questions

Why does log normalisation correct timestamps to UTC?+

Source systems often log in local time or drift from true time, so converting every entry to a common UTC baseline is necessary to place events from different systems in an accurate shared chronology.

What happens to an investigation if log normalisation is skipped?+

Analysts are left manually reconciling differing formats and field names by hand, which makes correlating events across sources slower and much more prone to error.

Related terms

Anchor Event
A log entry that can be identified with high confidence across two or more log sources, used to verify relative clock offsets...
Clock Skew
The difference between a device's local clock and a trusted reference time such as UTC. Skew accumulates due to hardware drift, timezone...
DHCP Lease Log
A record maintained by a Dynamic Host Configuration Protocol server that maps each IP address assignment to the requesting device's MAC address,...
NAT (Network Address Translation)
A mechanism by which a router replaces private source IP addresses with a single public IP address before forwarding packets to the...
Session Tuple
The five-element identifier for a network session: source IP, source port, destination IP, destination port, and protocol. The session tuple is the...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.