Events that result from fundamentally identical activities can be automatically grouped to make it easier to evaluate and hunt threats.
Similar events (Windows logons and Linux logons, for example) can be normalized as the same event type despite being generated from different rules.
Use the Normalized Dashboard view to see normalized events.
On the device tree, select the data source.
Click
to open the Policy Editor.In the Filters/Tagging panel, click
next to Normalized ID.Select a Normalized ID and close the Policy Editor.
Events from the selected data source appear on the Normalized Dashboard.