Skip to content

Adding an article on Iceberg / Parquet storage strategies.#137

Open
pagbabian-splunk wants to merge 1 commit into
mainfrom
pagbabian-splunk-patch-1
Open

Adding an article on Iceberg / Parquet storage strategies.#137
pagbabian-splunk wants to merge 1 commit into
mainfrom
pagbabian-splunk-patch-1

Conversation

@pagbabian-splunk
Copy link
Copy Markdown
Contributor

There are many ways to consume OCSF events. While the normative form is JSON, modern lakehouses use columnar storage in tabular forms. This article outlines some storage strategies that take advantage of OCSF framework features:

Storage by:

  • Product source
  • OCSF Class
  • OCSF Category
  • Hybrid Category & Observables

Signed-off-by: Paul Agbabian <pagbabian@splunk.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants