OTRF/OSSEM resource
Open Source Security Events Metadata (OSSEM) observed · 2026-08-28
Health v2 · maintenance only
32/100
- Activity 0
- Release rhythm 35
- Longevity 100
Flags: no_releases
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 3110
- days_rel: n/a
- days_push: 1283
- n_releases_24m: 0
Adoption not part of the score
1300 stars · 209 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
OSSEM is a community-led project that documents, standardizes, and models security event logs through data dictionaries, a common data model, and a detection model. It provides structured metadata about security event logs from Windows, Linux, macOS, Azure, AWS, and other sources to support log parsing and detection engineering.
Use cases
- standardize security event log field names across data sources
- normalize security logs into a common data model for SIEM pipelines
- look up field definitions for Windows, Linux, macOS, Azure, or AWS event logs
- map relationships among security events to build threat detection analytics
- validate detection coverage of adversary techniques against event data
- build a data wiki documenting security event logs in an organization
When to choose
- you are a detection engineer or threat hunter needing standardized log schemas
- you want to normalize heterogeneous security event logs into a common schema
- you need reference documentation for security event log fields and providers
- you are developing analytics and want event relationship models to guide detections
When to avoid
- you need a tool that actively parses or ingests logs rather than schema documentation
- you require a maintained product with frequent releases (latest release was early 2023)
- you need vendor-specific log formats not covered by the community dictionaries
Facets
dataset · maturity maintenance
documentation security parser data-science security documentation developer-tools cross-platform python security-event-logs data-dictionaries common-data-model detection-model siem threat-detection log-normalization metadata
1 source
- readme: https://github.com/OTRF/OSSEM · fetched 2026-08-28 · 37124466752e
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| OTRF/OSSEM | main | 32 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem