Just parsed raw data from an auth log on Ubuntu server to something more unified. Ingress authentications on Windows/Linux are now structured into the same format using Universal Event Format and unified into a dashboard on their incident response suite InsightIDR.

Some things need to be cleaned up though, notably the source IP.

It's more difficult to do unstructured auth logs, because you are most likely dealing with different types of key value pairs.

When you use EventLog for monitoring ingress to Windows servers you are already working with structured data.

