in SIEM
1 Answer

by
It is very difficult for human beings to analyse raw logs,so structured siem solutions conduct a process called event normalization to give a homogeneous view.Event normalization consists of breaking each field of a raw event into variables and combining them into views that are relevant to security administrators. This is a crucial step in the process of finding meaning in often isolated and heterogeneous events.

