Add OCSF mapping to parser
make_ocsf_mappingMap security logs to the OCSF standard using TQL parsing pipelines. Normalize data from multiple sources and get guidance on OCSF class selection and field mapping.
Instructions
Add OCSF mapping to a TQL parsing pipeline.
Use this tool when:
You need to map security logs to the OCSF standard
You're normalizing data from multiple sources into a common schema
You want to make your data compatible with OCSF-aware tools
You need guidance on OCSF class selection and field mapping
Follow the workflow instructions provided in the response.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| ctx | No | ||
| sample | Yes | Sample log events to generate OCSF mapping from |