Combine similar events to reduce processing time and storage requirements.
Events that are fundamentally the same can be grouped to make it easier to evaluate and hunt threats. For example, you can normalize Windows logins and Linux logins so they appear in the system simply as logins. Normalization is configured as part of Advanced Syslog Parser rule configuration.
Normalization IDs
Use normalized IDs to:
Filter using a single ID
Filter by multiple folders or IDs at one time (using the Ctrl or Shift keys to select).
Filter first-level folders
A mask (/5 for a first-level folder at the end of the ID) means Trellix ESM filters events by the selected subfolder IDs.
Filter second- or third-level folders
A mask (/12 for a second-level folder, /18 for a third-level folder at the end of the ID) means Trellix ESM filters events by the selected subfolder IDs.
Note
The fourth level doesn't have a mask.
String normalization
Use string normalization to:
Associate string values with alias values
Import or export a .csv file of normalized string values
Filter queries by strings and its aliases
For example, the John Doe user name string, define a string normalization file where the primary string is John Doe with the following aliases:
DoeJohn
JDoe
john.doe@gmail.com
JohnD
You can then create a query with John Doe as a user nickname and filter by string normalization.
The resulting view displays all events associated with John Doe and his aliases, enabling you to check for logon inconsistencies where source IPs match but user names do not.