Enter Password



aiFWall Logo aiFObserve

Distributed, Contextual Visibility & Governance for Enterprise AI Traffic. No Agents, No APIs, No

Generic SIEM OCSF CEF OTLP Capture Guide For Unified aiFObserve

Best Capture Source

Use OTLP JSON that preserves the original security event in attributes or body. If your SIEM exports CEF, LEEF, OCSF, ECS, CIM, or a vendor schema, keep both the normalized fields and the raw vendor event.

Basic Logging

Extended Logging

OCSF Notes

Keep class/category names, activity names, severity, disposition, actor/user, src_endpoint, dst_endpoint, http_request, cloud, and metadata fields.

CEF Notes

Keep CEF header values and extension fields such as:

OTLP Mapping Notes

OpenTelemetry logs include top-level timestamp, severity, body, resource, and attributes. Put normalized fields in attributes and preserve original event text in the body or event.original.

Source