Network Events
Overview
AlphaSOC normalizes network telemetry from various sources into the Open Cybersecurity Schema Framework (OCSF) format, enabling you to write consistent Sigma detection rules across different network monitoring tools and platforms. For complete field definitions and semantics, refer to the linked OCSF class schema pages.
Network: DNS
OCSF Category: Network Activity
OCSF Class: DNS Activity
OCSF Fields
activity_idactivity_nameactor.user.namecategory_namecategory_uidclass_nameclass_uiddevice.ipdevice.macdevice.uidmetadata.product.namemetadata.versionquery.hostnamequery.typercodercode_idseverityseverity_idtimetype_nametype_uid
Network: HTTP
OCSF Category: Network Activity
OCSF Class: HTTP Activity
OCSF Fields
actionaction_idactivity_idactivity_nameactor.user.nameapp_namecategory_namecategory_uidclass_nameclass_uiddevice.ipdevice.macdevice.uidhttp_request.http_headers.0.namehttp_request.http_headers.0.valuehttp_request.http_methodhttp_request.referrerhttp_request.url.url_stringhttp_request.user_agenthttp_response.codehttp_response.statusmetadata.product.namemetadata.versionseverityseverity_idstatusstatus_idtimetraffic.bytestraffic.bytes_intraffic.bytes_outtype_nametype_uid
Network: IP
OCSF Category: Network Activity
OCSF Class: Network Activity
OCSF Fields
activity_idactivity_nameactor.user.nameapp_namecategory_namecategory_uidclass_nameclass_uidconnection_info.directionconnection_info.direction_idconnection_info.protocol_nameconnection_info.protocol_numdevice.ipdevice.macdevice.uiddst_endpoint.ipdst_endpoint.portdurationmetadata.product.namemetadata.versionseverityseverity_idtimetraffic.bytestraffic.bytes_intraffic.bytes_outtraffic.packetstraffic.packets_intraffic.packets_outtype_nametype_uid
Network: TLS
OCSF Category: Network Activity
OCSF Class: Network Activity
OCSF Fields
activity_idactivity_nameactor.user.namecategory_namecategory_uidclass_nameclass_uiddevice.ipdevice.macdevice.uiddst_endpoint.ipdst_endpoint.portmetadata.product.namemetadata.versionseverityseverity_idtimetls.certificate.created_timetls.certificate.expiration_timetls.certificate.fingerprints.0.algorithm_idtls.certificate.fingerprints.0.valuetls.certificate.issuertls.certificate.subjecttls.ja3_hash.algorithm_idtls.ja3_hash.valuetls.ja3s_hash.algorithm_idtls.ja3s_hash.valuetype_nametype_uid