feat: transition events to OCSF format #703

Closed
opened 2026-03-28 04:27:37 +00:00 by mfreeman451 · 1 comment
Owner

Imported from GitHub.

Original GitHub issue: #2197
Original author: @mfreeman451
Original URL: https://github.com/carverauto/serviceradar/issues/2197
Original created: 2025-12-22T06:06:31Z


Is your feature request related to a problem?

we're currently transforming logs/traps/etc into cloudevents, need to get these in OCSF format

  • update zenrules
  • update zenrules in KV for syslog
  • zen rule for SNMP traps to OCSF
  • zen rules for falco, trivvy events (planned)

Describe the solution you'd like

Events typically flow in through collectors like snmp trapd, flowgger, netflow, falco (planned), trivvy (planned) and into the NATS JetStream message broker.

We generally use the zen-engine for ETL to convert these mesages to cloud events, need to switch this up to OCSF event format

Describe alternatives you've considered

A clear and concise description of any alternative solutions or features you've considered.

Additional context

Add any other context or screenshots about the feature request here.

Imported from GitHub. Original GitHub issue: #2197 Original author: @mfreeman451 Original URL: https://github.com/carverauto/serviceradar/issues/2197 Original created: 2025-12-22T06:06:31Z --- **Is your feature request related to a problem?** we're currently transforming logs/traps/etc into cloudevents, need to get these in OCSF format - [ ] update zenrules - [ ] update zenrules in KV for syslog - [ ] zen rule for SNMP traps to OCSF - [ ] zen rules for falco, trivvy events (planned) **Describe the solution you'd like** Events typically flow in through collectors like snmp trapd, flowgger, netflow, falco (planned), trivvy (planned) and into the NATS JetStream message broker. We generally use the zen-engine for ETL to convert these mesages to cloud events, need to switch this up to OCSF event format **Describe alternatives you've considered** A clear and concise description of any alternative solutions or features you've considered. **Additional context** Add any other context or screenshots about the feature request here.
Author
Owner

Imported GitHub comment.

Original author: @mfreeman451
Original URL: https://github.com/carverauto/serviceradar/issues/2197#issuecomment-3978681560
Original created: 2026-03-01T00:13:51Z


closing, completed

Imported GitHub comment. Original author: @mfreeman451 Original URL: https://github.com/carverauto/serviceradar/issues/2197#issuecomment-3978681560 Original created: 2026-03-01T00:13:51Z --- closing, completed
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
carverauto/serviceradar#703
No description provided.