FDR icon indicating copy to clipboard operation
FDR copied to clipboard

Standardize OCSF mapping rules format

Open Res260 opened this issue 1 year ago • 0 comments

The ocsf.py file implements a non-standard mapping rule definition. Since Crowdstrike is a contributor to OCSF, and the YAML-based approach is way better than using JSON to define mapping rules to translate to OCSF, it would be a good opportunity to standardize this format to be used to translate anything to OCSF, not just FDR.

See this discussion for details.

Res260 avatar Sep 25 '23 21:09 Res260