Skip to content

Normalisation

Definition

The process of converting log data from different vendors and formats into a common schema so that fields can be compared across sources. A timestamp from a Windows event log, a syslog entry, and a firewall log are mapped to a single time field in the SIEM's data model.

Purpose
Map varied log formats into one common schema
Example sources
Windows event log, syslog, firewall log
Output
Unified fields, e.g. a single time field, in the SIEM data model
Stage in pipeline
Occurs before correlation and alerting

Common questions

Why is normalisation necessary before logs can be correlated?+

Different systems record the same kind of event, such as a login, in different field names, formats, and timestamp conventions, and a correlation rule cannot compare a Windows Security Event ID to a firewall connection log unless both are first mapped into equivalent fields.

What can go wrong during log normalisation in a forensic investigation?+

A misconfigured or incomplete parser can drop, mistranslate, or misalign fields such as timezone offsets, silently corrupting the timeline an investigator relies on, so parser accuracy is normally validated before the SIEM's output is trusted as evidence.

Related terms

Alert Triage
The process of reviewing SIEM-generated alerts to determine which are genuine security events and which are false positives. In forensic investigations, alert...
Chain of Custody
The documented chronological record of who collected, handled, transferred, and examined a piece of evidence. For digital evidence, chain of custody includes...
Log Correlation
The process of matching related events from different log sources using shared attributes such as IP address, username, timestamp, or session ID....
Retention Policy
An organisation's rule specifying how long log data is stored before deletion or archiving. Policies are typically driven by compliance requirements and...
SIEM
Security Information and Event Management. A platform that ingests log streams from multiple sources, normalises them to a common schema, and applies...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.