Skip to content
Discussion options

You must be logged in to vote

Check out this article: https://github.com/ocsf/ocsf-docs/blob/main/articles/modeling-alerts.md

In general, you want to think of an IDS alert as a Detection Finding and set the is_alert field to true.

If regular events can be escalated into alerts, use the Security Control profile.

A Detection Finding is more high-level and has "container semantics", e.g., consider putting your contributing events into finding_info.related_events.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@pagbabian-splunk
Comment options

Answer selected by floydtree
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants