MOAR Stack · Well-connected
OCSF schema.
One normalized event model so a detection written once fires across sources. The mapping labor is the real cost, and the silent-loss failure modes are the trap.
Well-connected component · 8 essays
Listed from the front door down to the measured evidence. Start here marks the entry essay. The reading-level tag says whether you are reading the frame (Orientation), the argument (Depth), or a first-party finding (Evidence). The durability tag flags durable architecture versus an Evidence-pinned result tied to a version or price.
- Start here OrientationEvidence-pinned
Schema-on-read vs schema-on-write.
Splunk at $31K/month for 1 TB/day. Elasticsearch with ECS at $8–12K. Hybrid lakehouse (raw on cheap object storage, OCSF on warm) at $7.5K with parity on detection-engineer workflows. The schema-on-read tax compounds at retention scale.
Read →
- DepthDurable
The field-mapping anti-pattern.
Field-by-field mapping during SIEM-to-lakehouse migration looks like the safe play and drops detection coverage on the way. Five patterns that break and what to do instead.
Read →
- DepthDurable
Flattening away your detection logic.
Migrating from SIEM to lakehouse is semantic translation. Treating it as schema conversion is how detection coverage breaks: flattening CloudTrail's nested JSON silently broke a privilege-escalation detection for six weeks at a financial services firm.
Read →
- DepthEvidence-pinned
OCSF reverse mapping.
Answering the legal-team objection. When OCSF normalization erases the original-event fidelity required for chain-of-custody, here's how reverse-mapping preserves the evidentiary record.
Read →
- DepthEvidence-pinned
OCSF and operational technology.
OCSF has no native fields for Modbus, DNP3, BACnet, or S7comm. The Issue #1515 proposal adds six fields under an ics namespace, anchored on production-validated Zeek-to-OCSF mapping work. The architecture argument for IT/OT convergence at the schema layer.
Read →
- DepthEvidence-pinned
What two practitioners told me at RSA.
A field report, not a benchmark. Two RSA conversations where practitioners described both halves of the open architecture already running in production: petabyte-scale OCSF normalization on one side, columnar storage-and-query economics on the other. The mapping labor is the real cost, the numbers are attributed and discounted honestly, and field reports are weighed for what they can and can't tell you.
Read →
- EvidenceEvidence-pinned
Six schemas into OCSF: the mapping is the hard part.
Field-level crosswalks of Splunk CIM, Google Chronicle UDM, Microsoft Sentinel ASIM, Elastic ECS, OpenTelemetry, and Zeek into OCSF 1.8.0. The empty cells are the finding: five recurring seams, most of them the standard's own (missing disposition, missing certificate class, an invented-severity contract).
Read →
- EvidenceEvidence-pinned
LLM-assisted OCSF mapping.
What the migration tax actually looks like when you use LLMs to translate vendor schemas to OCSF. Where it accelerates, where it produces silent-loss errors, and how to validate.
Read →
Capability Matrix
The Matrix scores schema coverage and mapping fidelity against the crosswalk corpus.
See the Capability Matrix →