Skip to content

This reference provides comprehensive documentation for the Open Cybersecurity Schema Framework (OCSF), an open standard for normalizing security telemetry across tools and vendors.

We publish all OCSF schema versions with full cross-references between classes, objects, profiles, extensions, and types.

VersionClassesObjectsProfilesExtensionsTypes
v1.8.0-dev8317213224
v1.7.08317012224
v1.6.08216712224
v1.5.08116112224
v1.4.07914212222
v1.3.07212110222
v1.2.0651119222
v1.1.0501068222
v1.0.036846222

Tenzir provides native support for OCSF through the ocsf.* operators: ocsf.apply, ocsf.cast, ocsf.derive, and ocsf.trim. You can normalize events to OCSF, validate schema compliance, and work with OCSF-formatted data throughout your pipelines.

See the OCSF mapping workflow for guidance on creating custom mappings for your data sources.

Last updated: