--- slug: /cse/schema title: Cloud SIEM Schema description: Learn about Cloud SIEM Schema v3, schema attributes, and the record processing pipeline. canonical: https://www.sumologic.com/help/docs/cse/schema/ --- import useBaseUrl from '@docusaurus/useBaseUrl'; This guide has information about Cloud SIEM schemas. In this section, we'll introduce the following concepts:
Learn how Cloud SIEM transforms incoming raw messages into records.
Learn about Cloud SIEM schema attributes.
Learn what Cloud SIEM schema attributes you can map to records.
Learn about the record types to which you can map schema attributes.
Learn how to create a log mapping for structured messages.
Set up schema fields with an enforced, Cloud SIEM-defined output.
Set up field mappings for messages that you want to be processed by Cloud SIEM's normalized threat rules.
Learn how to use the Parser Editor to configure and test a custom parser.
Parsing is the first step in the Cloud SIEM record processing pipeline.
Learn about predefined named regular expressions used in regex-based parsers.
Learn about how Cloud SIEM normalizes usernames and hostnames during mapping and parsing.