Page
docs/spec/trace/extend_ocsf.md (lines 16, 106, 113), docs/spec/trace/events.md (line 59), specification/v0.1.0/trace/ocsf-mapping.json (class_name for agbom/snapshot and agbom/changed)
What is wrong or missing
The mapping labels class_uid 5001 as "Inventory Info". In OCSF 1.5 that class is "Device Inventory Info" and 5020 is "Software Inventory Info". The class_uid values are correct; only the class_name strings and the prose labels are stale, and the spec does not state which OCSF version its class names follow.
Two decisions for the Spec leads: (1) pin the OCSF version the mapping targets in the docs, and (2) either update the four class_name strings to the 1.5 names or record that the mapping intentionally uses the pre-1.5 label. Not changed in #63 because the label predates it. I can take this once the direction is chosen.
Current Priority Scope
This is deferred or out of scope and I am filing it to be tracked
Page
docs/spec/trace/extend_ocsf.md (lines 16, 106, 113), docs/spec/trace/events.md (line 59), specification/v0.1.0/trace/ocsf-mapping.json (
class_namefor agbom/snapshot and agbom/changed)What is wrong or missing
The mapping labels class_uid 5001 as "Inventory Info". In OCSF 1.5 that class is "Device Inventory Info" and 5020 is "Software Inventory Info". The
class_uidvalues are correct; only theclass_namestrings and the prose labels are stale, and the spec does not state which OCSF version its class names follow.Two decisions for the Spec leads: (1) pin the OCSF version the mapping targets in the docs, and (2) either update the four
class_namestrings to the 1.5 names or record that the mapping intentionally uses the pre-1.5 label. Not changed in #63 because the label predates it. I can take this once the direction is chosen.Current Priority Scope
This is deferred or out of scope and I am filing it to be tracked