In upcoming content releases, we will be addressing field mapping redundancies involving the following fields: device_hostname, device_ip, srcDevice_hostname, and srcDevice_ip. Currently, these normalized fields are sometimes derived from the same input source, leading to duplication.
The updates will streamline and standardize these mappings across the following product mappers, as well as any rules that generate signals from their records:
- AWS CloudTrail
- Cisco Umbrella
- Fortinet FortiGate
- Jamf
- Microsoft Office 365
- Microsoft Windows
- Okta
- Suricata
These refinements will help ensure consistent and efficient data normalization across supported sources.