Microsoft Sentinel
Cloud and workloads

Normalization

In brief

The page now links to the Agent Event schema and documents the Asset Entity schema for normalizing asset inventories and change feeds. The page date was also updated.

What Defender admins need to know

Administrators can more easily find guidance for normalizing agent-event and asset-inventory data; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As a security analyst, I want to use the Advanced Security Information Model (ASIM) so that I can normalize and correlate data from diverse sources for more efficient threat detection and investigation.

ASIM currently defines the following schemas:

ASIM also defines the Asset Entity schema for normalizing asset inventories and change feeds.

For more information, see ASIM schemas.

Query time parsers