Skip to content

This reference provides comprehensive documentation for the Open Cybersecurity Schema Framework (OCSF), an open standard for normalizing security telemetry across tools and vendors.

We publish all OCSF schema versions with full cross-references between classes, objects, profiles, extensions, and types.

VersionClassesObjectsProfilesExtensionsTypes
v1.7.07616611023
v1.6.07516311023
v1.5.07415711023
v1.4.07213811022
v1.3.0651179022
v1.2.0591088022
v1.1.0441037022
v1.0.033815022

Tenzir provides native support for OCSF through the ocsf.* operators: ocsf.apply, ocsf.cast, ocsf.derive, and ocsf.trim. You can normalize events to OCSF, validate schema compliance, and work with OCSF-formatted data throughout your pipelines.

Use Tenzir’s Claude plugins for guided OCSF mapping workflows.

Last updated: