Skip to main content

Field mappings and OCSF

Field mappings and OCSF

X
Written by Xero Risk

A risk field mapping is an account-authored rule: match kept normalized events, extract Work-Input or Work-Output, write an Asset series.

· Enable only the mappings you need. Unused mappings can be disabled from the tenant Admin Console.

· OCSF and other schemas work when your mapping paths match the fields you actually send. There is no automatic “OCSF certified” switch.

· `last_observed_at` on a mapping means live apply has seen matches. Missing observation is Unknown, not zero risk.

Mappings never copy raw ciphertext into reports or chat tools.

Did this answer your question?