ocsf

Retrieve OCSF schema documentation for event classes, objects, profiles, and data types.

3|Updated Mar 5, 2026
One-click install
npx skills add https://github.com/tenzir/skills --skill ocsf
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ocsf
Source: https://github.com/tenzir/skills/tree/main/skills/ocsf
Command: npx skills add https://github.com/tenzir/skills --skill ocsf

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill provides quick access to the Open Cybersecurity Schema Framework (OCSF) documentation, enabling users to understand and apply OCSF standards for security event normalization.

Core Features & Use Cases

  • Schema Navigation: Browse OCSF classes, objects, profiles, and data types across various versions.
  • Attribute Lookup: Understand OCSF naming conventions, attribute requirements, and data types.
  • Use Case: A security analyst needs to know the correct OCSF class for a firewall log. They can ask this Skill, which will then query the OCSF documentation to find the most appropriate class and its attributes.

Quick Start

Use the ocsf skill to find the OCSF class for firewall logs.

Frequently Asked Questions about ocsf

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is the OCSF schema and how does it help with security data normalization?

The OCSF schema is a framework for cybersecurity data normalization that provides standard event classes, objects, profiles, and data types to unify security event logs across different tools.

How do I find the correct OCSF class for a firewall log?

To find the correct OCSF class for a firewall log, query the OCSF schema reference to browse available event classes and their attributes, which matches your log data to the appropriate standard category.

Can I look up specific attribute requirements and naming conventions in OCSF?

Yes, you can look up OCSF naming conventions, attribute requirements, and data types by accessing the OCSF schema repository, which provides detailed documentation on object semantics and structure.

Does the OCSF schema reference support multiple framework versions?

The OCSF schema reference supports multiple versions, allowing you to browse event classes, objects, profiles, and data types across various iterations of the Open Cybersecurity Schema Framework.

What do I need to access the OCSF schema documentation for accurate information retrieval?

You need access to the OCSF schema repository to retrieve accurate reference information, as the skill queries this documentation to provide details on event classes, objects, and data types.