Optional _defaultThe default value to use if the source field is missing or empty.
Optional additionalA container for additional, undeclared properties. This is a holder for any undeclared properties as specified with the 'additionalProperties' keyword in the OAS document.
The destination OCSF field path.
Optional lookupLookup table configuration for mapping source values to destination values.
Optional sourceThe source field path from the log event.
Optional sourcesMultiple source field paths for combined mapping.
Optional valueA static value to use for the destination field.
Generated using TypeDoc
Defines a single field mapping rule for transforming a source field to an OCSF destination field.