Most organizations have several firewalls, proxies, DNS servers and identity systems from different vendors. Each logs the same kind of event with different table names, column names and values. One firewall calls the source address SrcIP, another src_ip, a third puts it inside a Syslog message. One says allow, another accept, a third permit. Writing every detection and hunt once per vendor does not scale, and a new product would silently fall outside all of them. The Advanced Security Information Model (ASIM) solves this by normalizing data, usually at query time. ASIM defines schemas for common event types, including network session, DNS, web session, authentication, process event, file event, registry event, audit event, user management and Dynamic Host Configuration Protocol (DHCP). Each schema has standard column names and value formats, for example SrcIpAddr, DstIpAddr, DstPortNumber and EventResult with values such as Success or Failure, so a query written once means the same thing for every source.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.