ocsf-schema
ocsf-schema copied to clipboard
Compatibility with OpenTelemetry semantic conventions and/or Elastic Common Schema
Elastic Common Schema defines a set of attributes for vulnerabilities, certificates, process, users, etc that has an intersection with OCSF. It was also historically actively used for security events.
OpenTelemetry defines a set of semantic conventions that describe specific events, implements distributed tracing, etc. It also provides extensive tooling to collect information from user applications or cloud providers. It also has a lot of intersection with OCSF around general-purpose data such as cloud resources, host, service, os, network peers, etc
Recently, ECS and OpenTelemetry announced convergence and will eventually provide a common set of attributes.
Given that security events are a subset of the general purpose events and have a lot of general attributes in common with OTel and ECS, what's the vision for OCSF?