Standardize on OCSF to run your own detection rules?

2 julian-datable 0 6/12/2025, 4:43:41 PM
Anyone adopted OCSF as their canonical logging schema?

Hoping to cut parsing overhead and make detection rule writing easier. Currently mapping 20-odd sources.

Any lessons/red flags you can share?

Comments (0)

No comments yet