Add OCSF mapping to parser
make_ocsf_mappingMap security logs to the OCSF standard to normalize data from multiple sources into a common schema, making it compatible with OCSF-aware tools.
Instructions
Add OCSF mapping to a TQL parsing pipeline.
Use this tool when:
You need to map security logs to the OCSF standard
You're normalizing data from multiple sources into a common schema
You want to make your data compatible with OCSF-aware tools
You need guidance on OCSF class selection and field mapping
Follow the workflow instructions provided in the response.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| sample | Yes | Sample log events to generate OCSF mapping from | |
| ctx | No |