Normalization - field names

I was going to write up a snippet on field names we should consider normalizing between different inputs as you get into Graylog and post it under miscellaneous of Templates and Rule Exchange rather than having others add after I forgot a few there - posting to the wild so you can add in reply here and I will coalesce for post into TRE in a couple of days. Initial field names to normalize below (feel free to suggest better fieldnames and/or explanation of why)

src_ip
dst_ip
target_host
target_user
error_text

I personally think those are good, but how about adding to your list?

Example:
src_port
dst_port

1 Like

Or maybe follow Graylog Information Model Schema?
https://schema.graylog.org/en/stable/index.html

1 Like

Well… yes… That is a much better list @shoothub… I must have missed that somewhere while I spent minutes pouring through documentation… :crazy_face:

I will post it up now - not much more to add! haha!

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.