ocsf-schema icon indicating copy to clipboard operation
ocsf-schema copied to clipboard

Use a Server Mode to add datetime_t Attributes Across Event Classes

Open pagbabian-splunk opened this issue 2 years ago • 0 comments

For the new datetime_t data type, Proposal 11 had a profile that would overlay a companion attribute everywhere there is a timestamp_t data type. Rather than use an actual profile, the schema server can have a switch or mode where this can be done globally (i.e. wherever there is a timestamp_t attribute in any event class). How that is detected via the API or schema is yet to be determined but I like the idea. Otherwise it is the same as Proposal 11. The original timestamp_t field must still be populated.

pagbabian-splunk avatar Aug 17 '22 03:08 pagbabian-splunk