Rule

rule

The Rule object describes characteristics of a rule associated with a policy or an event.

Attributes

CaptionNameTypeDescription
CategorycategoryString

The rule category.

DescriptiondescString

The description of the rule that generated the event.

NamenameString

The name of the rule that generated the event.

Raw Dataraw_dataJSON

Group:context
The event data as received from the event source.

Record IDrecord_idString

Group:primary
Unique identifier for the object

TypetypeString

The rule type.

Unique IDuidString

The unique identifier of the rule that generated the event.

UnmappedunmappedUnmapped[]

Data from the source that was not mapped into the schema.

VersionversionString

The rule version. For example: 1.1.

Relationships

Rule shown in context

Inbound Relationships

These objects and events reference Rule in their attributes:

Outbound Relationships

Rule references the following objects and events in its attributes:

This page describes ocsf-1.4.0