Standardize on OCSF to run your own detection rules?

4 months ago 70

Anyone adopted OCSF as their canonical logging schema?

Hoping to cut parsing overhead and make detection rule writing easier. Currently mapping 20-odd sources.

Any lessons/red flags you can share?

Read Entire Article