# Normalization - field names

**URL:** <https://community.graylog.org/t/normalization-field-names/21190>\
**Category:** Graylog Central (peer support)\
**Created:** [September 14, 2021, 3:42pm UTC](https://community.graylog.org/t/normalization-field-names/21190 "2021-09-14T15:42:54Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [September 14, 2021, 3:42pm UTC](https://community.graylog.org/t/normalization-field-names/21190/1 "2021-09-14T15:42:54Z")

</div>

I was going to write up a snippet on field names we should consider normalizing between different inputs as you get into Graylog and post it under miscellaneous of Templates and Rule Exchange rather than having others add after I forgot a few there - posting to the wild so you can add in reply here and I will coalesce for post into TRE in a couple of days. Initial field names to normalize below (feel free to suggest better fieldnames and/or explanation of why)

src\_ip  
dst\_ip  
target\_host  
target\_user  
error\_text

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [September 14, 2021, 10:39pm UTC](https://community.graylog.org/t/normalization-field-names/21190/2 "2021-09-14T22:39:01Z")

</div>

I personally think those are good, but how about adding to your list?

Example:  
src\_port  
dst\_port

---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [September 20, 2021, 8:09am UTC](https://community.graylog.org/t/normalization-field-names/21190/3 "2021-09-20T08:09:28Z")

</div>

Or maybe follow `Graylog Information Model Schema`?  
[https://schema.graylog.org/en/stable/index.html](https://schema.graylog.org/en/stable/index.html)

---

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [September 20, 2021, 12:38pm UTC](https://community.graylog.org/t/normalization-field-names/21190/4 "2021-09-20T12:38:34Z")

</div>

Well… yes… That is a much better list @shoothub… I must have missed that somewhere while I spent minutes pouring through documentation… 🤪

I will post it up now - not much more to add! haha!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [October 4, 2021, 12:39pm UTC](https://community.graylog.org/t/normalization-field-names/21190/5 "2021-10-04T12:39:33Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
