With the migration to ECS standard we can expect relative consistency across many fields. - [x] Identify dashboards which can be derived from these common fields - [x] Identify dashboards that are log specific (E.G protocols) - [x] Lessons learned from other NSM projects (Security Onion #73)/ElastiFlow/Synesis