OCSF Encoder
Encodes Arrow RecordBatches to Open Cybersecurity Schema Framework (OCSF) JSON format.
Configuration
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
codec | string | yes | — | Must be "ocsf" |
Example
sinks:
my_s3:
type: s3
bucket: security-events
prefix: ocsf/
encoding:
codec: ocsfWhen to Use
- Security analytics - Standardized security event format
- SIEM integration - Splunk, Sentinel, Chronicle
- Threat detection - Cross-platform security correlation