Standardize on OCSF to run your own detection rules?
2 julian-datable 0 6/12/2025, 4:43:41 PM
Anyone adopted OCSF as their canonical logging schema?
Hoping to cut parsing overhead and make detection rule writing easier. Currently mapping 20-odd sources.
Any lessons/red flags you can share?
No comments yet