Hey,
A quick explanation, we have clients with different SIEMs, and for each client different fields.
For example, one rule has "Username", and the other "user", "srcusr", "account", etc.
This causes some hard times when mapping the ontology entities.
I noticed that event fields can be edited (Edit Properties Metadata > Display name, system name,etc.)
From the events page I cannot edit the system name, only the Display name. But on the ontology page I still see only the actual system name.
Is there a way to map these multiple similar fields so that all will present only one fields on the ontology page? for the example above, only "User Name"?
or another example : SrcIP, src IP, src_ip > "Source IP"
Start changing that on the SIEM platforms can take a while and a lot of man power.