A city SOC wants one brute-force correlation to cover both the Palo Alto and Cisco ASA in front of the permitting portal. Analysts still paste vendor field names into every search. What is the SIEM best-practice next step?
Select an answer to reveal the explanation.
Short Explanation
Think of CIM like one shared street-address book for every brand of firewall. Once Palo and Cisco both speak src, dest, and action, one search covers both boxes. Pasting vendor fields into every search is rewriting the phone book for each new appliance.
Full Explanation
SIEM best practice is to normalize vendor telemetry to the Common Information Model first, then correlate on shared fields. Mapping both firewall sourcetypes to Network_Traffic lets one Enterprise Security search use src, dest, and action regardless of vendor. Per-search extractions and per-vendor ES apps do not scale when a new civic appliance is added. Offline spreadsheet joins discard the SIEM's purpose.