OCSF Schema
Apart from the eventlog schema, event log fields from multiple log sources are also normalized to the OCSF schema.
Note: For OCSF schema fields, array indexes start at array[1] and not array[0].
Anomali Search supports the following OCSF Version 1.2 classes:
-
OCSF System Activity Schema - Events related to system-level activities such as process creation, file operations, and kernel operations.
-
OCSF Findings Schema - Security findings, detections, and alerts from security tools.
-
OCSF Identity & Access Management Schema - Authentication, authorization, and identity-related events.
-
OCSF Network Activity Schema - Network connections, traffic, and protocol-level events.
-
OCSF Discovery Schema - Device and service discovery events, asset inventory.
-
OCSF Application Activity Schema - Application-level events including web requests, API calls, and application-specific operations.
See OCSF Schema Overview for more information about using OCSF with Anomali Search.