{"adoption": {"forks": 209, "observed_at": "2026-08-28T04:04:17.556339+00:00", "stars": 1300}, "canonical_url": "https://ross.abutalabs.com/products/ossem", "card": {"archived": false, "artifact_type": "dataset", "description": "Open Source Security Events Metadata (OSSEM)", "domain": ["security", "documentation", "developer-tools"], "enriched": true, "function": ["documentation", "security", "parser", "data-science"], "health_score": 20, "homepage": null, "language": "Python", "license": "MIT", "license_family": "permissive", "maturity": "maintenance", "member_repos": ["OTRF/OSSEM"], "name": "OTRF/OSSEM", "platform": ["cross-platform", "python"], "pushed_at": "2023-02-27T02:58:11+00:00", "repo": "OTRF/OSSEM", "stars": 1300, "tags": ["security-event-logs", "data-dictionaries", "common-data-model", "detection-model", "siem", "threat-detection", "log-normalization", "metadata"], "topics": [], "urls": [], "use_cases": ["standardize security event log field names across data sources", "normalize security logs into a common data model for SIEM pipelines", "look up field definitions for Windows, Linux, macOS, Azure, or AWS event logs", "map relationships among security events to build threat detection analytics", "validate detection coverage of adversary techniques against event data", "build a data wiki documenting security event logs in an organization"], "what_it_is": "OSSEM is a community-led project that documents, standardizes, and models security event logs through data dictionaries, a common data model, and a detection model. It provides structured metadata about security event logs from Windows, Linux, macOS, Azure, AWS, and other sources to support log parsing and detection engineering.", "when_to_avoid": ["you need a tool that actively parses or ingests logs rather than schema documentation", "you require a maintained product with frequent releases (latest release was early 2023)", "you need vendor-specific log formats not covered by the community dictionaries"], "when_to_choose": ["you are a detection engineer or threat hunter needing standardized log schemas", "you want to normalize heterogeneous security event logs into a common schema", "you need reference documentation for security event log fields and providers", "you are developing analytics and want event relationship models to guide detections"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/ossem", "repo": "OTRF/OSSEM", "role": "main", "score": 32}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:04:17.556339+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T04:52:17.245152+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "37124466752e0eb767e566586ba514fad74a81ff7e4980f92c5c975e43d07d36", "fetched_at": "2026-08-28T04:04:17.556339+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/OSSEM"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:04:17.556339+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T04:52:17.245152+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "37124466752e0eb767e566586ba514fad74a81ff7e4980f92c5c975e43d07d36", "fetched_at": "2026-08-28T04:04:17.556339+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/OSSEM"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T04:52:17.245152+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "37124466752e0eb767e566586ba514fad74a81ff7e4980f92c5c975e43d07d36", "fetched_at": "2026-08-28T04:04:17.556339+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/OSSEM"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:04:17.556339+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:04:17.556339+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:04:17.556339+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T04:52:17.245152+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "37124466752e0eb767e566586ba514fad74a81ff7e4980f92c5c975e43d07d36", "fetched_at": "2026-08-28T04:04:17.556339+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/OSSEM"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:04:17.556339+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:04:17.556339+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T04:52:17.245152+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "37124466752e0eb767e566586ba514fad74a81ff7e4980f92c5c975e43d07d36", "fetched_at": "2026-08-28T04:04:17.556339+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/OSSEM"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:04:17.556339+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:04:17.556339+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:04:17.556339+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T04:52:17.245152+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "37124466752e0eb767e566586ba514fad74a81ff7e4980f92c5c975e43d07d36", "fetched_at": "2026-08-28T04:04:17.556339+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/OSSEM"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:04:17.556339+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:04:17.556339+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T04:52:17.245152+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "37124466752e0eb767e566586ba514fad74a81ff7e4980f92c5c975e43d07d36", "fetched_at": "2026-08-28T04:04:17.556339+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/OSSEM"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T04:52:17.245152+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "37124466752e0eb767e566586ba514fad74a81ff7e4980f92c5c975e43d07d36", "fetched_at": "2026-08-28T04:04:17.556339+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/OSSEM"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T04:52:17.245152+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "37124466752e0eb767e566586ba514fad74a81ff7e4980f92c5c975e43d07d36", "fetched_at": "2026-08-28T04:04:17.556339+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/OSSEM"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T04:52:17.245152+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "37124466752e0eb767e566586ba514fad74a81ff7e4980f92c5c975e43d07d36", "fetched_at": "2026-08-28T04:04:17.556339+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/OSSEM"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["no_releases"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 3110, "days_push": 1283, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 32, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}