Skip to content

Findings/Security Finding/IBM/QRadar SIEM/offense.json is not valid OCSF? #32

@dfederschmidt

Description

@dfederschmidt

There seem to be various issues with this sample.

metadata.version is set to a value that is not reasonable. OCSF Version 7.5.0 does not exist.
https://github.com/ocsf/examples/blob/12802e239cc29016d267549e476d563b0b26bcc8/Findings/Security%20Finding/IBM/QRadar%20SIEM/offense.json#LL65C1-L66C1

severity_id - is a required property but is not set on the sample.

There may be various other issues but I stopped looking into using the sample after these 2 issues were uncovered. Just wanted to document this here in case someone else stumbles on this.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions