Logo
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Sign in
  1. Guardsix Servicedesk
  2. Products Hub
  3. Marketplace

JSON Normalizer

Standard

JSON Normalizer includes a JSONCompiledNormalizer that can normalize JSON logs while preserving the essential information in the nested structure. JSON Normalizer is designed to handle JSON logs efficiently and effectively when an integration doesn’t have a pre-built normalizer for JSON files. Whether or not to use the JSON Normalizer will depend on your use cases and requirements. One key advantage of using the JSON Normalizer is that it can provide faster performance and memory usage as it compiles the normalization rules into a specialized, optimized format that can be executed quickly and efficiently.

Release Details

Version: 5.1.3
Release date: 2024-01-13
Supported On: Logpoint v6.7.0 and later
SHA 256: c947adfacdf8bab429f5c5ee5604f94a58aeba2364051810efb369a017ed795a
JSON Normalizer Guide
Download

Key Information

  • The JSONCompiledNormalizer is generic, so you must put the normalization package at the end of the normalization policy along with other generic packages. 
  • JSON Normalizer provides minimal support for key renaming and labeling. For detailed guidance or assistance in customizing the data or sending JSON logs from any device, contact Logpoint Support.

Enhancements

KB-23277
You can now configure a date format for JSONCompiledNormalizer using CompiledNormalizer Date Preference (CNDP). To learn how, go to CNDP .
KB-2100274368
A raw log's field name containing hyphen (-) is replaced with underscore (_) when normalized by JSONCompiledNormalizer . For example, the Network_Message-ID field of a raw log is mapped as network-message-id .

Bug Fix

KB-2221777424
The eventTime field of a raw log was not mapped as log_ts field by JSONCompiledNormalizer.

Past Releases

JSON Normalizer v5.1.1 ▾
Version: 5.1.1
Supported On: Logpoint v6.7.0 and later
SHA 256: 0c5e0174a79568dfa717689824054df6082cc7c47ce5833f3c3f5a1c99ecf071
Download

Enhancement

KB-20254
Implemented a new error logging mechanism to identify and diagnose errors in the JSON data that prevents JSONCompiledNormalizer to correctly parse or process JSON logs.
JSON Normalizer v5.1.0 ▾
Version: 5.1.0
Supported On: LogPoint v6.7.0 and later
SHA 256: 4e0591539c4e3b7542f00ffe04e610bfc5f4e68d11492abeaf2476f3764c264c
Download

Bug Fixes

KB-1326756202
JSONCompiledNormalizer failed to normalize JSON logs when there was a space before curly braces.
KB-1610764213
JSONCompiledNormalizer did not normalize the MSG field.
KB-1700866774
JSONCompiledNormalizer removed the leading zeros. For instance, 000110101 was normalized as 110101 .

Support

If you have any questions or require assistance, create a support ticket.

Comments

  • Avatar
    Johan
    June 23, 2017 13:21

    You write that Windows is supported, but what kind of Windows event sources does it support? Does it support PowerShell, Sysmon, DNS, etc. that can log to the Windows event log?

    Comment actions Permalink
  • Avatar
    Permanently deleted user
    September 18, 2018 12:14

    Hello Johan,

    It supports any type the logs in JSON format with syslog header.

    Comment actions Permalink

Article is closed for comments.

Follow

Related articles

  • Universal Normalizer
  • Universal REST API Fetcher
  • Office365
  • ChatGPT Integration
  • Lookup
Consent Required To Proceed
By clicking “I Agree & Download”, you confirm that you are authorized to act on behalf of your organization and you give explicit consent for Guardsix to share your organization’s customer name and log source count with NXLog for the sole purposes of entitlement management, compliance verification, and support delivery related to the embedded NXLog technology in the Guardsix SIEM solution.

This data will not be used for sales or marketing and will not be shared with other third parties. You may withdraw your consent at any time by contacting Guardsix Support; withdrawal will not affect processing already performed.
Cancel I Agree & Download
Privacy policy    EULA    Terms of service   
Copyright © , Guardsix. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.