Normalization Reasons Complex Field

The Normalization Reasons table displays indicators that use the holistic data available in Axonius to hint why a record didn't correlate with others. The details displayed include:

  • Normalization Reason - The normalizer's name
  • Field name - The name of the field that is being correlated
  • Field Value - The value of the field
  • Calculated time - The time in the discovery cycle at which this was found
NormalizationReasonsTable

Below is a list of the reasons that can be displayed for different asset types.

Devices

  • Bad Hostnames By Cloud ID - Used to indicate that this hostname might be overlapping between multiple cloud assets. A Cloud ID should represent a single asset; a hostname seen with multiple Cloud IDs is suspected to be overlapping.
  • Bad Names By Cloud ID - Used to indicate that this asset name might be overlapping between multiple cloud assets. A Cloud ID should represent a single asset; an asset name seen with multiple Cloud IDs is suspected to be overlapping.
  • Bad Hostnames By Cloud Provider - Used to indicate that this hostname might be overlapping between multiple cloud providers. A hostname seen with multiple Cloud providers is suspected to be overlapping.
  • Bad Hostname By Serial - Used to indicate that this hostname might be overlapping between different devices. A Device Serial is normally a hardware identifier representing the BIOS serial, and as such, it should be unique. A Hostname that is related to multiple serial numbers is suspected to be overlapping.
  • Bad Hostnames By OS types - Used to indicate that this hostname might be overlapping between multiple OS types. A hostname seen with multiple OS types is suspected to be overlapping.
  • Bad Asset Names By OS types - Used to indicate that this asset name might be overlapping between multiple OS types. An asset name seen with multiple OS types is suspected to be overlapping.
  • Bad Serials By Hostnames - Used to indicate that this serial might be considered as not unique since it is related to multiple hostnames. A Device Serial is normally a hardware identifier representing the BIOS serial and as such, it should be unique.
  • Bad Serials By Asset Names - Used to indicate that this serial might be considered as not unique since it is related to multiple asset names. A Device Serial is normally a hardware identifier representing the BIOS serial and as such, it should be unique.
  • Bad Hostname By MachineID - Used to indicate that this Microsoft Defender hostname might be overlapping between multiple machine ids. A Machine ID should represent a single machine; a hostname seen with multiple Machine IDs is suspected to be overlapping.
  • Bad Name By Entra Object ID - Used to indicate that this device name might be overlapping between multiple Entra Object IDs. An Object ID should represent a single device within a tenant; a name seen with multiple Object IDs within the same tenant is suspected to be overlapping.
  • Bad Private IP By Domains - Used to indicate that this private IP might be overlapping across different domains. A private IP seen across multiple domains is suspected to be overlapping and should be ignored.
  • Bad VMware-ServiceNow Fields By AX-Unique-ID - Used to indicate that this unique ID might be overlapping between multiple VMware and ServiceNow adapter devices. Identifiers such as MAC addresses, hostnames, asset names, and serial numbers are used to detect overlaps.
  • Bad ServiceNow Hostnames By Agents - Used to indicate that this hostname or asset name might be overlapping between multiple serial numbers. A Device Serial is normally a hardware identifier representing the BIOS serial; a hostname or an asset name seen with multiple serial numbers is suspected to be overlapping.
  • Bad Infoblox Hostname By FQDN - Used to indicate that this Infoblox hostname might be invalid as its Fully Qualified Domain Name (FQDN) does not match. The hostname is ignored if there is a mismatch.
  • Bad IPs By Stacked Switch - Used to indicate that this IP address might belong to a stacked switch device and should be ignored.
  • Bad Phone Numbers By IMEI - Used to indicate that this phone number might be overlapping between multiple mobile devices based on their IMEIs. An IMEI is a unique identifier for a device; a phone number associated with multiple IMEIs is suspected to be non-unique within their environment.
  • Bad IMEI By Serial - Used to indicate that this IMEI might be overlapping between multiple devices based on their serial numbers. A serial number should uniquely identify a device; an IMEI associated with multiple serial numbers is suspected to be non-unique within their environment.
  • Bad Hostnames By HP NNMI Long Names - Used to indicate that this hostname might be overlapping between multiple devices based on long names provided by the HP NNMI adapter. A long name should be unique to a device; a hostname associated with multiple long names is suspected to be overlapping.
  • Bad Serials By ESX UUID - Used to indicate that this serial number might be overlapping between multiple devices based on their ESX UUIDs. A UUID should uniquely identify an ESX device; a serial number associated with multiple UUIDs is suspected to be non-unique within their environment.
  • Bad Bios Serials By Hostnames - Used to indicate that this BIOS serial might be overlapping between multiple devices based on their hostnames. A hostname should uniquely identify a device; a BIOS serial associated with multiple hostnames is suspected to be non-unique within their environment.
  • Bad Bios Serials By Asset Names - Used to indicate that this BIOS serial might be overlapping between multiple devices based on their asset names. An asset name should uniquely identify a device; a BIOS serial associated with multiple asset names is suspected to be non-unique within their environment.
  • Bad Hostnames By Rumble Sites - Used to indicate that this hostname might be overlapping between multiple devices based on Rumble site names. A site name should uniquely identify a group of devices; a hostname associated with multiple site names is suspected to be overlapping.
  • Bad Short Hostnames By FQDN - Used to indicate that this short hostname might be overlapping between multiple devices based on their Fully Qualified Domain Names (FQDNs). A short hostname should uniquely identify a device; a short hostname associated with multiple FQDNs is suspected to be non-unique within their environment.
  • Bad Short Asset Names By FQDN - Used to indicate that this short asset name might be overlapping between multiple devices based on their Fully Qualified Domain Names.
  • Bad AD Name By AD Guid - Used to indicate that this AD display name might be overlapping between multiple assets with different AD GUIDs. A display name shared by multiple AD GUIDs is suspected to be overlapping.
  • Bad FQDN By Cloud ID - Used to indicate that this FQDN might be overlapping between multiple assets with different Cloud IDs. An FQDN shared by multiple Cloud IDs is suspected to be overlapping.
  • Bad Hostnames By IMEI - Used to indicate that this hostname might be overlapping between multiple devices with different IMEIs. A hostname shared by multiple IMEIs is suspected to be overlapping.
  • Bad Asset Names By IMEI - Used to indicate that this asset name might be overlapping between multiple devices with different IMEIs. An asset name shared by multiple IMEIs is suspected to be overlapping.
  • Bad Hostnames By VMware UUID - Used to indicate that this hostname might be overlapping between multiple virtual machines with different VMware UUIDs. A hostname shared by multiple VMware UUIDs is suspected to be overlapping.
  • Bad Hostnames By Serial Many Adapters - Used to indicate that this hostname might be overlapping between multiple devices with different serial numbers across multiple adapters. A hostname shared by multiple serial numbers is suspected to be overlapping.
  • Bad Hostnames By Azure Subscription ID - Used to indicate that this hostname might be overlapping between multiple assets with different Azure Subscription IDs. A hostname shared by multiple Subscription IDs is suspected to be overlapping.
  • Bad Hostnames By ESX Duplicate Names - Used to indicate that this hostname might be overlapping between multiple machines identified in ESX. A hostname shared by multiple ESX machines is suspected to be overlapping.
  • Bad Names By ESX Duplicate Names - Used to indicate that this asset name might be overlapping between multiple machines identified in ESX. An asset name shared by multiple ESX machines is suspected to be overlapping.
  • Bad Hostnames By ServiceNow Duplicate Hostnames - Used to indicate that this hostname might be overlapping between multiple assets with different sys_ids in ServiceNow. A hostname shared by multiple sys_ids is suspected to be overlapping.
  • Bad Asset Names By ServiceNow Duplicate Asset Names - Used to indicate that this asset name might be overlapping between multiple assets with different sys_ids in ServiceNow. An asset name shared by multiple sys_ids is suspected to be overlapping.
  • Bad Hostnames By Jamf Duplicate Hostnames - Used to indicate that this hostname might be overlapping between multiple devices identified in Jamf. A hostname shared by multiple devices is suspected to be overlapping.
  • Bad Hostnames By Cherwell Printers - Used to indicate that this hostname might be overlapping between multiple printers identified in Cherwell. A hostname shared by multiple printers is suspected to be overlapping.

MAC Normalizer Reasons

The MAC Normalizer flags either an individual MAC address value, or a specific pair of correlated adapter records that share a MAC address, when that MAC address cannot be reliably trusted to identify a single unique device.

When a MAC address is flagged, the reason is displayed in the format Bad MAC <mac address> By <reason> - the MAC address itself is included in the reason text, followed by the specific reason listed below.

Unless stated otherwise, these reasons prevent MAC-only correlation. The flagged MAC address is still used for correlation when it is combined with other matching fields.

Some reasons are never reported on their own; they only appear alongside another corroborating reason for the same MAC address (for example, contradicting Names, contradicting OS). These reasons are marked below.

  • Bad MAC By blocklist - Used to indicate that this MAC address is a known invalid or placeholder value. The value either appears on a static list of known-bad MAC addresses, or matches one of several patterns that identify invalid or placeholder MAC formats. This check evaluates the MAC address value alone and does not depend on hostnames, serials, or any other field. Because the value itself can never be trusted, the MAC address is fully excluded from correlation across every adapter that reports it.
  • Bad MAC By characters too unique - Used to indicate that this MAC address is made up of fewer than three distinct characters overall (for example, 11:11:11:11:11:11 or AA:AA:AA:AA:AA:AA). Such low character diversity indicates a placeholder or test value rather than a genuine, vendor-assigned address, so the MAC address is excluded from correlation.
  • Bad MAC By non-correlative hardware - Used to indicate that the vendor of a MAC address (OUI) is known to belong to shared or interchangeable hardware - such as docking stations, KVM switches, USB-to-Ethernet adapters, shared network printers, or virtualization platforms - rather than the host machine's own built-in network adapter. The MAC address of hardware that is frequently swapped between different physical devices cannot be trusted to represent a single, unique asset. Manufacturers on the direct list of non-correlative vendors cause the MAC address to be excluded outright. VMware and a small set of additional manufacturers are used only as a secondary, corroborating signal alongside another contradiction, such as a hostname or serial number mismatch.
  • Bad MAC By contradicting Names - Used to indicate that this MAC address is reported by two different adapter records whose hostnames, or for certain adapters asset names, do not match. When the same MAC address is tied to two records with clearly different names, it is more likely to represent shared infrastructure - such as a hub, docking station, or virtual adapter - than a single physical device. Known exceptions are applied before flagging a contradiction, because some adapters legitimately report different hostnames for the same MAC address: ServiceNow-reported records, VMware-manufactured MAC addresses, Linux MAC addresses reported by Tenable IO, devices with a generic localhost hostname, and specific Cisco Meraki Chrome OS 32-character hostname cases.
  • Bad MAC By contradicting Serial Numbers - Used to indicate that this MAC address is shared between two adapter records that report different device serial numbers, meaning the MAC address does not uniquely correspond to a single physical device.
  • Bad MAC By contradicting Cloud IDs - Used to indicate that this MAC address is shared between two adapter records that report different Cloud IDs, meaning the MAC address does not uniquely correspond to a single cloud asset.
  • Bad MAC By non-correlative iOS Name by MobileIron - Used to indicate that this MAC address is shared between a MobileIron record and another adapter's record, where MobileIron reports the device as iOS with no hostname and only a generic asset name containing iPad or iPhone, while the other adapter reports a real, non-generic hostname for the same MAC address. A generic name such as iPad is not specific enough to confirm that the two records represent the same physical device.
  • Bad MAC By contradicting OS - Used to indicate that this MAC address is shared between two adapter records whose OS types contradict one another, for example Windows and Linux, or that both come from the same adapter. The same adapter reporting two different device records for the same MAC address is itself suspicious, unless that adapter is known to legitimately reuse MAC addresses across records. AWS, CarbonBlack Defense, Nexpose, and SentinelOne are excluded from this check. This reason is always reported together with another corroborating reason for the same MAC address.
  • Bad MAC By contradicting Windows Domains - Used to indicate that this MAC address is shared between two adapter records that are both Windows devices but report different domain values, indicating they are likely two different machines rather than one. This reason is always reported together with another corroborating reason for the same MAC address.
  • Bad MAC By non-correlative connection MAC - Used to indicate that this MAC address is involved in a contradiction where at least one side comes from an adapter known to report the MAC address of a network connection or interface rather than the physical device's own network adapter, such as network and asset discovery integrations including Microsoft Entra ID, Cisco Meraki, Infoblox, Qualys, Rapid7 InsightVM, Tenable IO, and Claroty. It also applies when both records come from this class of adapters, meaning neither side can be trusted as the authoritative source for the device's own MAC address. Apple-manufactured MAC addresses are excluded from the first case, because Apple exclusively manufactures its own hardware. This reason is always reported together with another corroborating reason for the same MAC address.
  • Bad MAC By non-correlative connection Host Name - Used to indicate that this MAC address is involved in a hostname contradiction where at least one side comes from an adapter known to report MAC addresses tied to a network connection rather than the device itself: Cisco Prime, Microsoft Defender for Endpoint, Fortinet FortiGate, SQL Assets Report, and Tanium Discover. Because these adapters report a connection point and not necessarily the reporting device, a hostname difference alongside one of these adapters is treated as an additional signal that the MAC address should not be trusted for correlation. This reason is always reported together with another corroborating reason for the same MAC address.
  • Bad MAC By contradicting CarbonBlack Basic Device ID - Used to indicate that this MAC address is shared between two CarbonBlack Defense adapter records that report an identical internal Basic Device ID but have contradicting hostnames. A matching Basic Device ID with a different hostname suggests that the CarbonBlack agent ID was reused on a different physical host, for example after an agent reinstall on new hardware, so the MAC address is not used to link the two records. This reason is always reported together with another corroborating reason for the same MAC address.

Users

  • Bad Usernames By Last Name - Used to indicate that this username might be overlapping between multiple users. A user has only one last name; a username seen with multiple last names is suspected to be overlapping.
  • Bad Mails By Employee ID - Used to indicate that this mail might be overlapping between multiple employee IDs. A unique mail address is associated with a single employee (user); a mail seen with multiple employee IDs is suspected to be overlapping.
  • Bad Mails By Username - Used to indicate that this mail might be overlapping between multiple users. A username should represent a single user; a mail seen with multiple usernames is suspected to be overlapping.
  • Bad Mails by Service Account - Used to indicate that this mail belongs to a service account and won't be used for correlation. Service accounts are identified based on common patterns in the Organizational Unit and Display Name fields reported by Microsoft Active Directory and ServiceNow.

Did this page help you?