Skip to main content
OCSF TA for Linux app icon

OCSF TA for Linux

This TA provides you with the capability to search your events using OCSF compliant fields, as well as CIM to support your current use cases. This includes specifically Auditd for the moment, as this is the most important data source because it ties everything from your STIG/CIS to your security use cases in Linux.Built by Arkitech Security
splunk product badge

Default Version 2.3.3

July 17, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 8.x

Rating
0
(0)

Log in to rate this app

Support
Developer Supported
Ranking

#18 in Artificial Intelligence

This TA provides you with the capability to search your events using OCSF compliant fields, as well as CIM to support your current use cases. This includes specifically Auditd for the moment, as this is the most important data source because it ties everything from your STIG/CIS to your security use cases in Linux.