ocsf-schema icon indicating copy to clipboard operation
ocsf-schema copied to clipboard

Compatibility with OpenTelemetry semantic conventions and/or Elastic Common Schema

Open lmolkova opened this issue 1 year ago • 3 comments

Elastic Common Schema defines a set of attributes for vulnerabilities, certificates, process, users, etc that has an intersection with OCSF. It was also historically actively used for security events.

OpenTelemetry defines a set of semantic conventions that describe specific events, implements distributed tracing, etc. It also provides extensive tooling to collect information from user applications or cloud providers. It also has a lot of intersection with OCSF around general-purpose data such as cloud resources, host, service, os, network peers, etc

Recently, ECS and OpenTelemetry announced convergence and will eventually provide a common set of attributes.

Given that security events are a subset of the general purpose events and have a lot of general attributes in common with OTel and ECS, what's the vision for OCSF?

lmolkova avatar Sep 06 '23 17:09 lmolkova