What is normalised log data?¶
Normalised data maps different vendor records into a common schema for cross-source search and comparison. The common label is a platform interpretation, not guaranteed equivalence of meaning.
Mapping trades nuance for consistency¶
Fields such as src_ip, clientAddress and origin may become one source-address field. Some values lack exact equivalents, several states can be grouped, and original detail may be discarded. “Login success” can conceal primary authentication, token refresh or session continuation.
Return to source for detailed conclusions¶
Identify normalising platform, parser and version, source event, field map and transformations. Preserve both normalised and raw records.
Use the common schema to find patterns, then verify important fields and ensure apparently matching labels across systems represent the same stage and observation.
The point to remember
Normalisation supports discovery across products; source fields and mapping rules support precise interpretation.