Skip to content

Commit 95af12a

Browse files
Update _posts/2025-03-05-OpenSearch-as-a-SIEM-Solution.md
Co-authored-by: Nathan Bower <[email protected]> Signed-off-by: DattellConsulting <[email protected]>
1 parent 720f509 commit 95af12a

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

_posts/2025-03-05-OpenSearch-as-a-SIEM-Solution.md

+1-1
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,7 @@ OpenSearch is well suited for log analysis because it can ingest and index massi
4444

4545
Security teams benefit from being able to query recent and historical logs in one place. For example, an analyst can query web server logs, DNS logs, and authentication logs simultaneously to investigate an incident, something that would be cumbersome if those logs resided in separate silos.
4646

47-
### <u>Data Normalization.</u>
47+
### <u>Data normalization</u>
4848
Data normalization is important for building generalizable detection rules and dashboards that work across different log sources. When aggregating logs from many sources, a common challenge is that each source has its own format (different field names and structures). OpenSearch’s Security Analytics plugin includes field mappings for common log types.[1](https://opensearch.org/docs/latest/security-analytics/#:~:text=Security%20Analytics%20is%20a%20security,responding%20effectively%20to%20potential%20threats) Additionally, OpenSearch allows users to define mappings and ingest pipelines to normalize data.
4949

5050
### <u>Data Visualization.</u>

0 commit comments

Comments
 (0)