Update docs for better information on constructing and using arrays#132
Update docs for better information on constructing and using arrays#132pagbabian-splunk merged 5 commits intoocsf:mainfrom
Conversation
Start array's modification for clarity and examples Signed-off-by: Jason Reimer <jason.reimer@tanium.com>
add an intro and adjust formatting Signed-off-by: Jason Reimer <jason.reimer@tanium.com>
try to emulate Paul's writing style. Signed-off-by: Jason Reimer <jason.reimer@tanium.com>
add array information to faq Signed-off-by: Jason Reimer <jason.reimer@tanium.com>
|
Hello @floydtree! What do you think of these changes. This is based upon all the questions that came up again when creating gpu_info_list. |
|
hey @pagbabian-splunk on the Understanding OCSF how would you like to handle the date field |
Hi @jasonbreimer I have a few other tweaks I need to make (and have been lax on doing) so thanks for the reminder. I will get that date change done as part of it. Hopefully by this weekend. |
pagbabian-splunk
left a comment
There was a problem hiding this comment.
Looks very good!
|
@jasonbreimer this is fantastic, just a couple minor comments |
Replaced IP examples with existing OCSF attributes (finding_info / finding_info_list) to better show changes. Updated Dated and Version Signed-off-by: Jason Reimer <jason.reimer@tanium.com>
Summary
This PR modifies the Understanding OCSF and Schema FAQ documentation for arrays, describing how arrays should be modeled and populated in OCSF.
Changes Included
Pending Changes