2022-12-12 08:54 PM
Hi,
In the version of 12.1.0.0 of NetWitness,
in Respond, there are original alerts and normalized alerts.
Simply speaking, what is the difference between original alerts and normalized alerts ?
Regards,
2022-12-16 08:45 AM
Hi @susui
Original alerts are basically raw alerts respond receives from ESA.
Once the raw alert comes into respond, it goes through a process called normalization which is basically mapping fields from raw alert to user known meta keys. The end alert info you see in UI is normalized alert data.
You can refer this - https://community.netwitness.com/t5/netwitness-platform-online/configure-custom-respond-server-alert-normalization/ta-p/669575
2022-12-16 08:45 AM
Hi @susui
Original alerts are basically raw alerts respond receives from ESA.
Once the raw alert comes into respond, it goes through a process called normalization which is basically mapping fields from raw alert to user known meta keys. The end alert info you see in UI is normalized alert data.
You can refer this - https://community.netwitness.com/t5/netwitness-platform-online/configure-custom-respond-server-alert-normalization/ta-p/669575